<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Liberu CRM (0.9.1 - 9.9.9) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/liberu-crm-0.9.1---9.9.9/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 20:30:13 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/liberu-crm-0.9.1---9.9.9/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Broken Access Control in Liberu CRM via Team Invitation Logic</title><link>https://feed.craftedsignal.io/briefs/2026-09-liberu-crm-broken-access-control/</link><pubDate>Tue, 29 Sep 2026 20:30:13 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-liberu-crm-broken-access-control/</guid><description>Liberu CRM versions 0.9.1 through 10.0.0 are vulnerable to privilege escalation via a broken access control flaw in the team invitation workflow, allowing users with pending invites to provision unauthorized administrator accounts.</description><content:encoded><![CDATA[<p>Liberu CRM versions 0.9.1 through 10.0.0 contain a broken access control vulnerability (CVE-2026-61519) within the <code>TeamPolicy::addTeamMember()</code> function. The vulnerability stems from a flawed authorization predicate that incorrectly grants invitation rights based solely on the presence of a pending team invitation. An attacker holding a valid pending invitation for a low-privilege team role can exploit this logic to invite secondary attacker-controlled accounts with elevated administrative privileges. Upon the acceptance of these crafted invitations, the secondary accounts are provisioned with full administrative create, read, update, and delete access to all team-scoped data. This vulnerability bypasses intended privilege-level validation within the <code>InviteTeamMember</code> component, presenting a significant risk of unauthorized data access and integrity compromise for organizations utilizing the affected software.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthorized users to achieve full administrative control over team-scoped data. This can lead to the exfiltration of sensitive organizational information, modification of team records, and long-term persistence within the application environment. The severity is marked as high (CVSS 8.8) due to the ease of exploitation and the depth of access granted upon compromise.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Liberu CRM to version 10.0.0 or later immediately to apply the patch for CVE-2026-61519.</li>
<li>Audit existing team memberships for anomalies, specifically checking for recently added administrative accounts that do not correlate with legitimate organizational hiring or team changes.</li>
<li>Review web server logs for suspicious POST requests to the <code>team-invitations</code> API endpoint that contain elevated role parameters associated with users who lack administrative status.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>