UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard
48Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 9.3epss 0.3%
de la publicación al arma1 días
Publicada en NVD16 sept
1ª PoC+1d
probabilidad de explotación
0.3%top 72% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
uvdesk · community-skeletonPoCs públicas encontradas — 1
githubgithub.com/cflowsec/CVE-2026-92805★ 0⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://github.com/uvdesk/community-skeletonhttps://github.com/uvdesk/community-skeleton/blob/6f35040/src/Resources/config/routes.yaml#L1-L35https://github.com/uvdesk/community-skeleton/issues/926https://www.vulncheck.com/advisories/uvdesk-community-skeleton-through-1.1.8-missing-authentication-on-the-installation-wizard