Description
UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized manipulation of ticket ratings by authenticated users
Action: Patch Immediately
AI Analysis

Impact

UVdesk support‑center‑bundle before version 1.1.3.3 contains an insecure direct object reference that allows an authenticated customer to submit or change satisfaction ratings on tickets that do not belong to them. The rateTicket action loads arbitrary ticket identifiers without verifying ownership, meaning a user can arbitrarily elevate or lower the rating of another user’s ticket. This flaw can distort business metrics, undermine the integrity of the support service, and potentially skew revenue reporting.

Affected Systems

The vulnerability is present in the uvdesk community‑skeleton package and its support‑center‑bundle component. Any deployment using these components prior to the 1.1.3.3 release is susceptible; later releases include an ownership check that removes the flaw.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity data‑integrity weakness. EPSS data is not available, so the likelihood of active exploitation cannot be quantified from publicly available metrics, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread attacks yet. The attack requires an authenticated user and consists of sending a request to the rateTicket endpoint with a ticket identifier that belongs to another customer. No privilege escalation or remote code execution is possible; the impact is limited to the integrity of ticket ratings and the downstream processes that rely on them.

Generated by OpenCVE AI on October 3, 2026 at 00:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the UVdesk support‑center‑bundle package to version 1.1.3.3 or later so that an ownership check is enforced.
  • If an upgrade is not immediately possible, apply the patch from commit 3fa884a3adf0f317f354f83a1f9fa531234a551f to your codebase and redeploy the application.
  • Deploy a temporary controller‑level check that verifies the ticket belongs to the currently authenticated user before accepting the rating, until a proper version upgrade or official patch can be applied.

Generated by OpenCVE AI on October 3, 2026 at 00:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 23:30:00 +0000

Type Values Removed Values Added
Description UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers.
Title UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint
First Time appeared Uvdesk
Uvdesk community-skeleton
Weaknesses CWE-639
CPEs cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*
Vendors & Products Uvdesk
Uvdesk community-skeleton
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Uvdesk Community-skeleton
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T23:28:49.296Z

Reserved: 2026-10-02T21:13:54.347Z

Link: CVE-2026-105029

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T00:16:36.463

Modified: 2026-10-03T00:16:36.463

Link: CVE-2026-105029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T01:00:15Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key