Eleveo Call Recording Software Query Builder searchAction.do access control
Published Sep 28, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.20%
Description
A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/searchAction.do of the component Query Builder. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
Affected
- 9.7.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Eleveo | Call Recording Software | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://drive.google.com/file/d/16y5IDrRDrARBtGETXUHhkSgFN38b-c6C/view?usp=sharing exploit
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88475 Advisory
- https://vuldb.com/cve/CVE-2026-101144 third-party-advisory
- https://vuldb.com/submit/894910 third-party-advisory
- https://vuldb.com/vuln/410996 vdb-entry
- https://vuldb.com/vuln/410996/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://drive.google.com/file/d/16y5IDrRDrARBtGETXUHhkSgFN38b-c6C/view?usp=sharing | exploit | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88475 | Advisory | |
| https://vuldb.com/cve/CVE-2026-101144 | third-party-advisory | |
| https://vuldb.com/submit/894910 | third-party-advisory | |
| https://vuldb.com/vuln/410996 | vdb-entry | |
| https://vuldb.com/vuln/410996/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data