{"id":"CVE-2026-59234","title":"Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calendar/CalendarDeleteEventController.php), exposed at GET /calendar/event/delete/{id}, in Prospero Flow CRM before 5.5.3 …","summary":"Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calendar/CalendarDeleteEventController.php), exposed at GET /calendar/event/delete/{id}, in Prospero Flow CRM before 5.5.3 …","severity":"none","cwe":["CWE-639"],"published":"2026-07-03","updated":"2026-07-03","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59234","references":[{"url":"https://github.com/Roskus/prospero-flow-crm/commit/8c26eed4d80544c30e55448e12a8e999af6d2b70","label":"4daa8cea-433a-44bd-9456-53b127fc289a"},{"url":"https://github.com/Roskus/prospero-flow-crm/releases/tag/v5.5.3","label":"4daa8cea-433a-44bd-9456-53b127fc289a"},{"url":"https://secur0.com/en/cna/cve-list/cve-2026-59234-idor-in-prospero-flow-crm-allows-deletion-of-other-users-calendar-events","label":"4daa8cea-433a-44bd-9456-53b127fc289a"}],"tags":["nvd"],"ingestedAt":"2026-07-04T09:56:00.577Z","epss":0.00641,"epssPercentile":0.49345,"slug":"CVE-2026-59234","body":"## Overview\n\nAuthorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calendar/CalendarDeleteEventController.php), exposed at GET /calendar/event/delete/{id}, in Prospero Flow CRM before 5.5.3 allows a remote, authenticated attacker to delete arbitrary calendar events belonging to other users by manipulating the {id} path parameter, because the delete handler resolves the record with Calendar::find($id)->delete() and performs no ownership check (no user_id/company_id scoping) before deletion. This results in unauthorized destruction of other users' calendar events across the platform.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}