Description
Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the Support Agent assignment field of tickets by bypassing intended authorization checks. Attackers can add or remove any user, including Superadmin accounts, from the Support Agent field of any ticket to which they are assigned, circumventing role-based access controls.
Published: 2026-07-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a broken access control flaw that enables authenticated attackers with Agent-level privileges to alter the support agent assignment field on any ticket they can view, bypassing intended authorization checks. By adding or removing any user, including Superadmin accounts, an attacker can re‑assign tickets, potentially redirecting work or gaining unauthorized visibility. This flaw, identified as CWE-862, undermines the integrity of ticket ownership and can facilitate privilege escalation or data exposure.

Affected Systems

Ultimate Fosters Perfect Support Ticketing & Document Management System version 1.7 is affected. Users with Agent‑level roles who can log in to the system may exploit this issue by changing ticket assignments that they are authorized to view.

Risk and Exploitability

The CVSS score of 5.3 marks a medium severity, and the EPSS score of <1% indicates a very low, yet non‑zero, likelihood of exploitation. The vulnerability is not listed in CISA KEV. Exploitation requires that the attacker be an authenticated user with Agent privileges; they can then manipulate the assignment field on any accessible ticket. Based on the description, it is inferred that the attack vector is an authenticated in‑application request that bypasses role‑based checks.

Generated by OpenCVE AI on July 31, 2026 at 01:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Perfect Support Ticketing & Document Management System to the latest version that contains the vendor patch for CVE‑2026‑63082.
  • Restrict Agent‑level permissions by enforcing least privilege and ensuring only trusted users can modify the Support Agent field.
  • Enable audit logging for all ticket assignment changes and configure alerts for anomalous activity to detect potential exploitation.

Generated by OpenCVE AI on July 31, 2026 at 01:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Ultimate Fosters
Ultimate Fosters perfect Support Ticketing & Document Management System
Vendors & Products Ultimate Fosters
Ultimate Fosters perfect Support Ticketing & Document Management System

Thu, 16 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the Support Agent assignment field of tickets by bypassing intended authorization checks. Attackers can add or remove any user, including Superadmin accounts, from the Support Agent field of any ticket to which they are assigned, circumventing role-based access controls.
Title Perfect Support Ticketing System 1.7 Broken Access Control via Agent Assignment
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ultimate Fosters Perfect Support Ticketing & Document Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-16T16:15:50.464Z

Reserved: 2026-07-15T15:45:44.600Z

Link: CVE-2026-63082

cve-icon Vulnrichment

Updated: 2026-07-16T16:15:45.672Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T02:00:05Z

Weaknesses