CVE-2026-61519P2HIGHCVSS 8.8≥ 0.9.1, < 10.0.02026-09-29
CVE-2026-61519 [HIGH] CWE-863 CVE-2026-61519: Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user h
Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team invitation to invite additional attacker-controlled accounts with elevated privileges by exploiting a flawed authorization predicate in TeamPolicy::addTeamMember() that grants invitation rights based solely on the existence of a pe
nvd