PT-2026-64034 · Itflow · Itflow
CVE-2026-47755
·
Published
2026-07-23
·
Updated
2026-07-23
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ITFlow versions prior to 26.05
Description
Low-privileged authenticated agents can retrieve plaintext credentials and TOTP (Time-based One-Time Password) secrets belonging to other clients. This occurs because the endpoint used to request the credential edit modal does not enforce client scoping or object-level authorization before loading and decrypting the record when an arbitrary
credential id is provided.Recommendations
Update to version 26.05.
Exploit
Fix
Missing Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Itflow