CVE-2026-61519 Details
Description
Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team invitation to invite additional attacker-controlled accounts with elevated privileges by exploiting a flawed authorization predicate in TeamPolicy::addTeamMember() that grants invitation rights based solely on the existence of a pending invitation email match. Attackers can send a POST request to the team-invitations route specifying the admin role for a second account, bypassing privilege-level validation in InviteTeamMember, causing the second account upon invitation acceptance to be attached to the team with full admin-level create, read, update, and delete access over all team-scoped data.
A broken access control vulnerability has been identified in Liberu CRM versions 0.9.1 prior to 10.0.0. This vulnerability allows users with a pending team invitation to exploit a flawed authorization process in the TeamPolicy::addTeamMember() function. By doing so, they can invite additional accounts with elevated privileges. The vulnerability arises because the authorization check only verifies the existence of a pending invitation email, without properly validating the role being assigned. As a result, an attacker can send a POST request to the team-invitations route, specifying an admin role for a second account. Once the invitation is accepted, the account gains full administrative access to all team-related data, including creation, reading, updating, and deletion rights.
Users can upgrade to Liberu CRM version 10.0.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/liberusoftware/crm-laravel/commit/0846d067ae2e9c437e8555e54a4ec6517927b3d4 | [email protected] | Source CodeVendor |
| https://github.com/liberusoftware/crm-laravel/issues/708 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/liberusoftware/crm-laravel/releases/tag/v10.0.0 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/liberu-crm-broken-access-control-via-teampolicy-addteammember | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Liberu CRM | >= 0.9.1, < 10.0.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion