MEDIUM 6.3

CVE-2026-15374: Eleveo Call Recording Software Authorization Flaw

Eleveo Call Recording Software version 9.7.0 contains an authorization flaw in its Group Interface component. An authenticated attacker can manipulate requests to the /callrec/roleAddAction.do endpoint to bypass access controls, potentially gaining unauthorized actions within the system. The vulnerability requires valid user credentials but can be exploited remotely without user interaction. Public exploit code is available.

Source data · NVD / CISA · public domain

CVSS
3.1 · 6.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Weaknesses (CWE)
CWE-266, CWE-285
Affected products
0 configuration(s)
Published / Modified
2026-07-10 / 2026-07-13

NVD description (verbatim)

A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/roleAddAction.do of the component Group Interface. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

5 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-15374 is an improper authorization vulnerability (CWE-266, CWE-285) affecting Eleveo Call Recording Software 9.7.0. The flaw exists in the Group Interface component, specifically the /callrec/roleAddAction.do endpoint. An authenticated attacker can manipulate this function to circumvent authorization checks, resulting in unauthorized access or actions. The attack vector is network-accessible, requires low complexity, and necessitates valid authentication credentials (PR:L). The vulnerability carries a CVSS v3.1 score of 6.3 (MEDIUM severity) with potential impact to confidentiality, integrity, and availability.

Business impact

This vulnerability enables privilege escalation and lateral movement within Eleveo deployments. Authenticated users—including those with minimal privileges—could manipulate group role assignments or access controls, potentially affecting call recording configurations, audit trails, and data access policies. In multi-tenant or regulated environments, unauthorized role manipulation could compromise compliance postures, expose sensitive call data, or allow attackers to obscure their activities. Organizations relying on Eleveo's access controls for enforcement of data governance face direct risk.

Affected systems

Eleveo Call Recording Software version 9.7.0 is confirmed affected. Organizations running this version should assume they are at risk. Verify your installed version against your license or administrative interface. Earlier and later versions may also be affected; contact Eleveo or consult their security advisories for comprehensive version coverage. The vendor did not respond to early disclosure, so formal vendor guidance may be limited.

Exploitability

Public exploit code is available, reducing the barrier to weaponization. The attack requires valid credentials, which limits scope to insider threats or attackers with prior access compromise. Network accessibility and low complexity mean that anyone with valid authentication can launch the attack without complex prerequisites or user interaction. The combination of public exploit availability and low authentication barrier makes this vulnerability practically exploitable in real-world scenarios.

Remediation

Immediately verify your Eleveo Call Recording Software version. If running 9.7.0, prioritize patching to a patched version as soon as available from the vendor. Because the vendor did not respond to early disclosure, check Eleveo's official security advisories or website for patch availability and compatibility details. In the interim, implement network segmentation to restrict access to the /callrec/roleAddAction.do endpoint, enforce strong access controls, and monitor for suspicious role or group modification attempts.

Patch guidance

Contact Eleveo directly or monitor their official security page for patch releases addressing CVE-2026-15374. Verify patch version numbers and compatibility with your deployment before applying. Given the vendor's lack of response during disclosure, patches may be delayed; establish a timeline for remediation and communicate interim mitigations to stakeholders. Test patches in a non-production environment first to ensure compatibility with your call recording workflows.

Detection guidance

Monitor authentication logs for unusual authentication patterns, especially from service accounts or low-privilege users. Track HTTP requests to /callrec/roleAddAction.do for POST or manipulation attempts with unexpected parameters. Alert on successful group or role modifications initiated by non-administrative accounts or outside normal change windows. Review Eleveo access logs for unauthorized changes to role assignments, group memberships, or permission configurations. Implement baseline logging of all /callrec/ endpoint activity if not already enabled.

Why prioritize this

Although unranked on CISA's KEV catalog, this vulnerability warrants prompt attention due to public exploit availability, the relative ease of exploitation (authenticated access only), and the severity of the authorization flaw. In call recording systems—often subject to regulatory requirements—unauthorized role manipulation poses compliance and data governance risks. The vendor's non-responsiveness increases uncertainty about patch timelines, making proactive remediation essential.

Risk score, explained

The CVSS v3.1 score of 6.3 (MEDIUM) reflects the attack's network accessibility, low complexity, and impact to confidentiality, integrity, and availability. However, the score's reliance on the PR:L (Privileged Required: Low) parameter may understate risk in environments where service accounts are numerous or credential compromise is common. The presence of public exploit code elevates practical risk beyond the base CVSS metric. Organizations with strong privileged access management (PAM) can mitigate some risk; those without should treat this as MEDIUM-HIGH.

Frequently asked questions

Is Eleveo Call Recording Software 9.7.0 the only affected version?

The CVE documentation specifically lists 9.7.0 as affected. Eleveo has not publicly disclosed whether earlier or later versions are vulnerable. Check the vendor's security advisories or contact their support team to confirm the full range of affected versions. Do not assume other versions are safe without verification.

Can this vulnerability be exploited without authentication?

No. The vulnerability requires valid user credentials to access the /callrec/roleAddAction.do endpoint. However, this does not limit risk significantly in environments where user accounts are numerous, shared, or compromised. Attackers with any legitimate authentication can exploit the flaw.

What should we do if we cannot patch immediately?

Implement compensating controls: restrict network access to the /callrec/roleAddAction.do endpoint using firewalls or WAF rules, enforce multi-factor authentication, monitor and alert on role/group modifications, and review audit logs daily for anomalies. These are temporary measures; plan and execute patching as soon as a fix is available.

Why did the vendor not respond to early disclosure?

The vendor's lack of response during the disclosure process is unusual and concerning. This may indicate resource constraints, internal disruption, or deprioritization of security. Regardless, this highlights the importance of establishing your own detection and remediation timeline rather than waiting for vendor guidance. Consider escalating your urgency accordingly.

This analysis is based on available vulnerability data as of the publication date and does not constitute professional security advice. Patch versions, vendor advisories, and affected product details should be verified directly with Eleveo. Organizations should conduct their own risk assessment based on their deployment, regulatory obligations, and threat model. SEC.co makes no warranty regarding the completeness or accuracy of this intelligence. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).