CVE-2026-101144: fallo de gravedad media en Eleveo Call Recording Software
Eleveo Call Recording Software Query Builder searchAction.do access control
Publicada el · Actualizada el
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 5.3epss 0.2%
probabilidad de explotación
0.2%top 91% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/searchAction.do of the component Query Builder. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
Eleveo · Call Recording SoftwarePoCs públicas encontradas — 1
cve_referencedrive.google.com/file/d/16y5IDrRDrARBtGETXUHhkSgFN38b-c6C/view?usp=sharingno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
CVEs relacionadas — Eleveo Call Recording Software
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-15375MEDIUMEleveo Call Recording Software LDAP User users_ldap.jsp improper authorizationEPSS 0.4%CVE-2026-15474MEDIUMEleveo Call Recording Software audio.jsp improper authorizationEPSS 0.3%CVE-2026-15472MEDIUMEleveo Call Recording Software composeEmailAction.do improper authorizationEPSS 0.3%CVE-2026-15471MEDIUMEleveo Call Recording Software pci_dss_status.jsp improper authorizationEPSS 0.3%CVE-2026-15470MEDIUMEleveo Call Recording Software group.jsp improper authorizationEPSS 0.3%CVE-2026-15377MEDIUMEleveo Call Recording Software sendlogfile improper authorizationEPSS 0.3%