CVE-2026-105029: medium-severity vulnerability in uvdesk support-center-bundle
UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.2%
exploitation probability
0.2%top 91% of all CVEs
observed exploitation
nono source reports it
UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Related CVEs — uvdesk support-center-bundle
In the same product, most dangerous first.
CVE-2026-92805CRITICALUVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation WizardEPSS 0.6%CVE-2025-71421HIGHUVdesk core-framework before 1.1.7 Privilege Escalation via editAgentEPSS 0.4%CVE-2025-71420MEDIUMUVdesk core-framework before 1.1.7 Authorization Bypass via Saved ReplyEPSS 0.3%CVE-2025-71419MEDIUMUVdesk core-framework before 1.1.7 Stored XSS via SwiftMailerEPSS 0.2%
References
https://github.com/uvdesk/support-center-bundlehttps://github.com/uvdesk/support-center-bundle/commit/3fa884a3adf0f317f354f83a1f9fa531234a551fhttps://hackmd.io/@leediay/idor-rate-ticket_uvdeskhttps://www.vulncheck.com/advisories/uvdesk-support-center-bundle-before-1.1.3.3-idor-via-rateticket-ticket-rating-endpoint