Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-19871: Prospero Flow CRM employee onboarding uses insecure default password
CVE-2026-19871 · published 20 days ago
Summary
Prospero Flow CRM's employee onboarding process in older versions uses a default password for all employees, making it easy for unauthorized users to access employee accounts if they know the email address. This is a security risk for companies that use this software. To fix this, update to the latest version of Prospero Flow CRM, which includes a password change requirement for new employees.
What to do
- Update roskus prospero flow crm to version 5.15.9 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| roskus | prospero flow crm | < 5.15.9 |
Original advisory text
Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through th...
Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password "changeme" and the onboarding form provides no password field.
Severity
9.3
Critical
Exploitation
EPSS <1%
Type
CWE-798Use of Hard-coded Credentials
Timeline
Published14 Aug 2026
Updated30 Aug 2026
First seen14 Aug 2026
Monitor software like this
Free during beta