A vulnerability categorized as critical has been discovered in Roskus Prospero Flow CRM up to 5.15.8. This issue affects the function employee save controller of the component Human Resources. Such manipulation leads to hard-coded credentials.

This vulnerability is referenced as CVE-2026-19871. It is possible to launch the attack remotely. No exploit is available.

It is advisable to upgrade the affected component.