cve-2026-77759
Brief
IDOR and missing authorization in the Prospero Flow CRM transaction API allow cross-tenant reading of financial records
IDOR and missing authorization in the Prospero Flow CRM transaction API allow cross-tenant reading of financial records