Broken Access Control in Liberu CRM via Team Invitation Logic
Liberu CRM versions 0.9.1 through 10.0.0 are vulnerable to privilege escalation via a broken access control flaw in the team invitation workflow, allowing users with pending invites to provision unauthorized administrator accounts.
CVE search metadata
CVE search record: CVE-2026-61519. Severity: high. CVSS: 8.8. KEV: no. Product: Liberu CRM (0.9.1 - 9.9.9). Brief: Broken Access Control in Liberu CRM via Team Invitation Logic. Brief link: https://feed.craftedsignal.io/briefs/2026-09-liberu-crm-broken-access-control/
Liberu CRM versions 0.9.1 through 10.0.0 contain a broken access control vulnerability (CVE-2026-61519) within the TeamPolicy::addTeamMember() function. The vulnerability stems from a flawed authorization predicate that incorrectly grants invitation rights based solely on the presence of a pending team invitation. An attacker holding a valid pending invitation for a low-privilege team role can exploit this logic to invite secondary attacker-controlled accounts with elevated administrative privileges. Upon the acceptance of these crafted invitations, the secondary accounts are provisioned with full administrative create, read, update, and delete access to all team-scoped data. This vulnerability bypasses intended privilege-level validation within the InviteTeamMember component, presenting a significant risk of unauthorized data access and integrity compromise for organizations utilizing the affected software.
Impact
Successful exploitation of this vulnerability allows unauthorized users to achieve full administrative control over team-scoped data. This can lead to the exfiltration of sensitive organizational information, modification of team records, and long-term persistence within the application environment. The severity is marked as high (CVSS 8.8) due to the ease of exploitation and the depth of access granted upon compromise.
Recommendation
- Upgrade Liberu CRM to version 10.0.0 or later immediately to apply the patch for CVE-2026-61519.
- Audit existing team memberships for anomalies, specifically checking for recently added administrative accounts that do not correlate with legitimate organizational hiring or team changes.
- Review web server logs for suspicious POST requests to the
team-invitationsAPI endpoint that contain elevated role parameters associated with users who lack administrative status.
Immediate actions
Upgrade Liberu CRM to 10.0.0 or later
Threat Hunt
Search logs for POST requests to team-invitation endpoints from non-admin users adding members with admin roles
Data: Web server logs (POST /team-invitations)
Mitigations
Upgrade to Liberu CRM 10.0.0
CVE-2026-61519