UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance. | |
| Title | UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard | |
| First Time appeared |
Uvdesk
Uvdesk community-skeleton |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Uvdesk
Uvdesk community-skeleton |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:32:54.622Z
Reserved: 2026-09-16T19:47:14.880Z
Link: CVE-2026-92805
No data.
Status : Received
Published: 2026-09-16T21:17:30.267
Modified: 2026-09-16T21:17:30.267
Link: CVE-2026-92805
No data.
OpenCVE Enrichment
No data.
Weaknesses