CVE-2026-101144: medium-severity vulnerability in Eleveo Call Recording Software
Eleveo Call Recording Software Query Builder searchAction.do access control
Published · Updated
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.2%
exploitation probability
0.2%top 91% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/searchAction.do of the component Query Builder. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
Eleveo · Call Recording Softwarepublic PoCs found — 1
cve_referencedrive.google.com/file/d/16y5IDrRDrARBtGETXUHhkSgFN38b-c6C/view?usp=sharingunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — Eleveo Call Recording Software
In the same product, most dangerous first.
CVE-2026-15375MEDIUMEleveo Call Recording Software LDAP User users_ldap.jsp improper authorizationEPSS 0.4%CVE-2026-15474MEDIUMEleveo Call Recording Software audio.jsp improper authorizationEPSS 0.3%CVE-2026-15472MEDIUMEleveo Call Recording Software composeEmailAction.do improper authorizationEPSS 0.3%CVE-2026-15471MEDIUMEleveo Call Recording Software pci_dss_status.jsp improper authorizationEPSS 0.3%CVE-2026-15470MEDIUMEleveo Call Recording Software group.jsp improper authorizationEPSS 0.3%CVE-2026-15377MEDIUMEleveo Call Recording Software sendlogfile improper authorizationEPSS 0.3%