Description
A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations belonging to other customers via the v1 REST API. The API verifies the existence of the requested ticket but not ownership, enabling any authenticated user to access arbitrary ticket threads including internal agent notes containing sensitive information.
Published: 2026-08-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A broken access control flaw exists in Ladybird Web Solution’s Faveo Helpdesk version 2.0.3. The v1 REST API fails to verify ticket ownership before returning ticket details, allowing any authenticated user to read the entire conversation history of any ticket, including internal agent notes that may contain sensitive information. This results in a confidentiality breach of customer records and internal communications.

Affected Systems

The vulnerability affects Ladybird Web Solution Faveo Helpdesk version 2.0.3, specifically the endpoints of the v1 REST API that provide ticket details. No other versions or components are listed as affected in the current CNA data.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, so the exact exploitation probability cannot be quantified, but the flaw is exploitable by any authenticated user using normal API calls, making exploitation straightforward. The vulnerability is not listed in CISA’s KEV catalog as of the last update. Prompt remediation is recommended to protect customer and agent data.

Generated by OpenCVE AI on August 11, 2026 at 16:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Ladybird Web Solution Faveo Helpdesk to the latest release that contains the access control fix.
  • If an upgrade is not immediately possible, restrict the v1 REST API to internal users or administrators only to prevent customers from accessing tickets that are not theirs.
  • Add application‑level verification to confirm ticket ownership before returning any conversation data to the client.

Generated by OpenCVE AI on August 11, 2026 at 16:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Ladybirdweb
Ladybirdweb faveo Helpdesk
Vendors & Products Ladybirdweb
Ladybirdweb faveo Helpdesk

Tue, 11 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations belonging to other customers via the v1 REST API. The API verifies the existence of the requested ticket but not ownership, enabling any authenticated user to access arbitrary ticket threads including internal agent notes containing sensitive information.
Title Ladybird Web Solution Faveo Helpdesk - Broken Access Control
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ladybirdweb Faveo Helpdesk
cve-icon MITRE

Status: PUBLISHED

Assigner: TuranSec

Published:

Updated: 2026-08-11T15:17:06.829Z

Reserved: 2026-08-10T10:32:49.081Z

Link: CVE-2026-72554

cve-icon Vulnrichment

Updated: 2026-08-11T15:17:02.424Z

cve-icon NVD

Status : Received

Published: 2026-08-11T12:17:41.103

Modified: 2026-08-11T16:17:35.790

Link: CVE-2026-72554

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:45:03Z

Weaknesses