{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/liberu-crm-0.9.1---9.9.9/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:liberu:crm:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-61519"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Liberu CRM (0.9.1 - 9.9.9)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Liberu"],"content_html":"\u003cp\u003eLiberu CRM versions 0.9.1 through 10.0.0 contain a broken access control vulnerability (CVE-2026-61519) within the \u003ccode\u003eTeamPolicy::addTeamMember()\u003c/code\u003e function. The vulnerability stems from a flawed authorization predicate that incorrectly grants invitation rights based solely on the presence of a pending team invitation. An attacker holding a valid pending invitation for a low-privilege team role can exploit this logic to invite secondary attacker-controlled accounts with elevated administrative privileges. Upon the acceptance of these crafted invitations, the secondary accounts are provisioned with full administrative create, read, update, and delete access to all team-scoped data. This vulnerability bypasses intended privilege-level validation within the \u003ccode\u003eInviteTeamMember\u003c/code\u003e component, presenting a significant risk of unauthorized data access and integrity compromise for organizations utilizing the affected software.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized users to achieve full administrative control over team-scoped data. This can lead to the exfiltration of sensitive organizational information, modification of team records, and long-term persistence within the application environment. The severity is marked as high (CVSS 8.8) due to the ease of exploitation and the depth of access granted upon compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Liberu CRM to version 10.0.0 or later immediately to apply the patch for CVE-2026-61519.\u003c/li\u003e\n\u003cli\u003eAudit existing team memberships for anomalies, specifically checking for recently added administrative accounts that do not correlate with legitimate organizational hiring or team changes.\u003c/li\u003e\n\u003cli\u003eReview web server logs for suspicious POST requests to the \u003ccode\u003eteam-invitations\u003c/code\u003e API endpoint that contain elevated role parameters associated with users who lack administrative status.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T20:30:13Z","date_published":"2026-09-29T20:30:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-liberu-crm-broken-access-control/","summary":"Liberu CRM versions 0.9.1 through 10.0.0 are vulnerable to privilege escalation via a broken access control flaw in the team invitation workflow, allowing users with pending invites to provision unauthorized administrator accounts.","title":"Broken Access Control in Liberu CRM via Team Invitation Logic","url":"https://feed.craftedsignal.io/briefs/2026-09-liberu-crm-broken-access-control/"}],"language":"en","title":"CraftedSignal Threat Feed - Liberu CRM (0.9.1 - 9.9.9)","version":"https://jsonfeed.org/version/1.1"}