No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 30 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liberu Software
Liberu Software liberu Crm |
|
| Vendors & Products |
Liberu Software
Liberu Software liberu Crm |
Wed, 30 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team invitation to invite additional attacker-controlled accounts with elevated privileges by exploiting a flawed authorization predicate in TeamPolicy::addTeamMember() that grants invitation rights based solely on the existence of a pending invitation email match. Attackers can send a POST request to the team-invitations route specifying the admin role for a second account, bypassing privilege-level validation in InviteTeamMember, causing the second account upon invitation acceptance to be attached to the team with full admin-level create, read, update, and delete access over all team-scoped data. | |
| Title | Liberu CRM 0.9.1 < 10.0.0 Broken Access Control via TeamPolicy::addTeamMember() | |
| Weaknesses | CWE-863 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-30T19:27:52.083Z
Reserved: 2026-07-10T15:43:36.628Z
Link: CVE-2026-61519
Updated: 2026-09-30T19:27:32.122Z
Status : Deferred
Published: 2026-09-29T20:17:21.150
Modified: 2026-09-30T20:17:33.807
Link: CVE-2026-61519
No data.
OpenCVE Enrichment
Updated: 2026-09-30T20:39:29Z