CVE-2026-15375: Eleveo Call Recording Software 9.7.0 Authorization Bypass
Eleveo Call Recording Software version 9.7.0 contains an authorization flaw in its LDAP user management interface that allows authenticated users to access or view information they shouldn't be permitted to see. The vulnerability is accessible over the network and requires valid credentials to exploit. Public details about this vulnerability are available, increasing the risk of opportunistic attacks against unpatched installations.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Weaknesses (CWE)
- CWE-266, CWE-285
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-10 / 2026-07-14
NVD description (verbatim)
A vulnerability has been found in Eleveo Call Recording Software 9.7.0. This impacts an unknown function of the file /callrec/users_ldap.jsp of the component LDAP User Interface. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
6 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-15375 is an improper authorization vulnerability (CWE-266, CWE-285) residing in the /callrec/users_ldap.jsp endpoint within Eleveo Call Recording Software 9.7.0's LDAP user interface component. The flaw permits authenticated users to bypass authorization controls and gain unauthorized access to sensitive information. The CVSS v3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) indicates network accessibility, low attack complexity, requirement for valid user credentials, and confidentiality impact limited to the user's session scope.
Business impact
Organizations relying on Eleveo Call Recording Software may face data exposure risks if internal users with basic call recording system access exploit this flaw to view call records, user lists, or LDAP directory information beyond their assigned role. This could violate compliance requirements (HIPAA, PCI-DSS, SOX) if sensitive communications or customer data are exposed. The lack of integrity or availability impact limits the immediate operational risk, but unauthorized information disclosure can lead to privacy breaches, regulatory fines, and reputational damage.
Affected systems
Eleveo Call Recording Software version 9.7.0 is confirmed vulnerable. Organizations using this version should assume risk until patching is available. Earlier and later versions should be evaluated against vendor advisories to confirm scope. The vulnerability requires the attacker to already possess valid system credentials, limiting the exposure surface to insider threats or compromised internal accounts.
Exploitability
This vulnerability has been publicly disclosed and exploitation details are available, raising the practical risk of use by both skilled attackers and less sophisticated threat actors. Exploitation requires valid login credentials—an authenticated user can trigger the authorization bypass without user interaction via a network request. The low attack complexity and absence of special conditions make it straightforward to exploit once access is gained. However, the need for pre-existing credentials creates a necessary prerequisite that somewhat constrains immediate risk.
Remediation
Contact Eleveo immediately to obtain a patched version addressing CVE-2026-15375. Verify the fix in vendor advisories or security notices before deployment. If no patch timeline is announced, consider implementing network segmentation to restrict LDAP interface access to administrative users only, and enforce strict role-based access control (RBAC) within the application. Review LDAP user permissions and audit access logs for unauthorized queries. Until patching, monitor authentication and authorization events in the call recording system for anomalies.
Patch guidance
Verify with Eleveo's official advisory for availability and version numbers of patched releases. Deploy patches in a test environment first to validate compatibility with your call recording workflows. Eleveo's silence on this disclosure (as noted in the vulnerability record) suggests engaging support directly may be necessary to obtain patch status and timelines. Schedule patching according to your change management process, prioritizing production systems handling sensitive communications.
Detection guidance
Monitor access logs for /callrec/users_ldap.jsp for requests from unexpected user accounts or roles. Audit LDAP query patterns and lookups for signs of enumeration or data exfiltration. Set alerts on failed and successful authentication attempts to the LDAP interface, especially from non-administrative accounts. Review user session logs for privilege escalation or lateral movement following login. Log analysis tools and SIEM platforms should correlate repeated requests to the vulnerable endpoint with user activity baselines.
Why prioritize this
Although the CVSS score is medium (4.3), the public availability of exploit details, confirmed vendor unresponsiveness, and the specific risk of insider information disclosure warrant prompt attention. Organizations handling regulated communications data should treat this as higher priority due to compliance exposure. The requirement for valid credentials reduces immediate external threat, but insider risk and compromised account scenarios elevate priority in security-sensitive environments.
Risk score, explained
The CVSS v3.1 score of 4.3 (Medium) reflects limited confidentiality impact, no integrity or availability impact, and a requirement for authenticated access. The score appropriately weights the barrier of needing valid credentials against the ease of exploitation once those credentials are obtained. The publicly disclosed status and vendor silence increase practical risk beyond the base score, warranting contextual risk elevation based on your threat model and data sensitivity.
Frequently asked questions
Does this vulnerability allow remote code execution or system takeover?
No. CVE-2026-15375 is limited to unauthorized information disclosure. It does not enable code execution, privilege escalation to administrative levels, or availability disruption. An attacker can view data they shouldn't access, but cannot modify system configurations or take the system offline.
Can this be exploited by someone without any access to Eleveo?
No. The vulnerability requires valid login credentials to the call recording system. An attacker must either compromise an existing user account or find another way to obtain valid authentication. This makes external attack by unknown parties unlikely, but increases risk from disgruntled insiders or lateral movement by attackers already on the network.
What should I do if I'm still on version 9.7.0 and can't patch immediately?
Contact Eleveo support urgently to confirm patch availability and timelines. In the interim, restrict network access to the /callrec/users_ldap.jsp endpoint to administrative users only using firewall rules or web application firewalls. Enforce multi-factor authentication for system accounts and audit access logs regularly. Monitor for suspicious LDAP queries or unusual data access patterns.
Is this vulnerability in the CISA Known Exploited Vulnerabilities (KEV) catalog?
No, CVE-2026-15375 is not currently listed in CISA's KEV catalog, despite public disclosure. This does not diminish the need to patch—KEV status indicates active in-the-wild exploitation tracking by CISA, not a measure of overall criticality. Prioritize based on your environment's exposure and data sensitivity.
This analysis is provided for informational purposes and represents SEC.co's interpretation of publicly available data as of the publication date. Verify all patch versions, vendor advisories, and timeline information directly with Eleveo's official security channels before implementation. CVE details and CVSS scores should be validated against the official NVD entry and vendor advisories. Security teams should conduct their own risk assessment based on their specific environment, data classification, and threat model. No exploit code or proof-of-concept demonstrations are provided; focus remediation efforts on patching and access control enforcement. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10070MEDIUMmacrozheng mall Admin Authorization Bypass in /admin/update/
- CVE-2026-10215MEDIUMDolibarr Leave Request API Authorization Bypass
- CVE-2026-10218MEDIUMGoClaw Improper Authorization Vulnerability (CVSS 5.4)
- CVE-2026-10269MEDIUMHost Header Authorization Bypass in Decolua 9router
- CVE-2026-10272MEDIUMStudent-Management-System Authorization Bypass in Admin Panel
- CVE-2026-10282MEDIUMBottelet DaybydayCRM Authorization Bypass in DocumentsController
- CVE-2026-10284MEDIUMImproper Authorization in DevaslanPHP Project-Management Comment Functions
- CVE-2026-10285MEDIUMDevaslanPHP Improper Authorization in Ticket Handler