Impact
A broken access control flaw in BadChoice Handesk’s TicketsController@update endpoint allows any authenticated agent to modify ticket records of other teams without authorization checks. The missing authorize() call and lack of team‑scoped ownership validation mean an attacker holding any agent account could alter, elevate, or corrupt tickets belonging to teams outside their remit, thereby compromising data integrity and potentially enabling higher‑level privilege escalation. This weakness aligns with CWE‑284, which describes improper authorization mechanisms that can lead to unauthorized access or modification of resources.
Affected Systems
The vulnerability affects BadChoice’s Handesk product. The issue applies to the release available as of 2026-07-10; no specific version numbers are disclosed in the advisory, but any instance running that release or earlier is potentially susceptible.
Risk and Exploitability
The CVSS score of 8.1 indicates a high‑severity concern. The EPSS score is not provided, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited publicly known exploitation yet the flaw is exploitable by anyone with agent credentials. Because the attack vector requires authenticated access, the risk is concentrated against internal or compromised users, but once exploited, the integrity of ticket data across the organization can be severely impacted.
OpenCVE Enrichment