A vulnerability was found in Roskus Prospero Flow CRM up to 5.15.9. It has been declared as critical. This affects an unknown part of the component Payroll Module. The manipulation results in authorization bypass.
This vulnerability was named CVE-2026-19870. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.