Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/searchAction.do of the component Query Builder. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Eleveo Call Recording Software Query Builder searchAction.do access control | |
| First Time appeared |
Eleveo
Eleveo call Recording Software |
|
| Weaknesses | CWE-266 CWE-284 |
|
| CPEs | cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Eleveo
Eleveo call Recording Software |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-28T20:00:07.419Z
Reserved: 2026-09-28T08:11:27.828Z
Link: CVE-2026-101144
No data.
Status : Received
Published: 2026-09-28T21:17:12.153
Modified: 2026-09-28T21:17:12.153
Link: CVE-2026-101144
No data.
OpenCVE Enrichment
Updated: 2026-09-28T21:30:07Z