Description
A vulnerability was found in Eleveo Quality Management 9.7.0. This issue affects some unknown processing of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. The manipulation of the argument labels results in denial of service. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-04
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A defect was discovered in Eleveo Quality Management version 9.7.0 that allows an attacker to manipulate the argument labels supplied to the /enc-fwk-data/api/v3/conversations/<ID>/events API endpoint. This manipulation causes the Conversation Handler component to enter an error state that can be repeated to exhaust resources, resulting in a denial of service. The flaw is classified as an Improper Resource Management issue (CWE‑404).

Affected Systems

Eleveo Quality Management 9.7.0 is the only version explicitly mentioned as vulnerable. No other versions or product variants were listed in the available data.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog, yet a public exploit has been documented. The attack vector is remote, relying on HTTP requests to the vulnerable API endpoint. Because the flaw can be triggered without privileged access, anyone on the network or the internet (depending on exposure) can potentially disrupt the service.

Generated by OpenCVE AI on September 4, 2026 at 05:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Eleveo Quality Management patch as soon as it is released.
  • If a patch is not yet available, limit or validate the argument labels accepted by the /enc-fwk-data/api/v3/conversations/<ID>/events endpoint to prevent malformed input.
  • Configure rate‑limiting or a web application firewall to mitigate repeated calls that could exhaust the service.
  • Monitor logs for abnormal traffic or repeated failures to detect ongoing exploitation attempts.

Generated by OpenCVE AI on September 4, 2026 at 05:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Eleveo Quality Management 9.7.0. This issue affects some unknown processing of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. The manipulation of the argument labels results in denial of service. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Eleveo Quality Management Conversation events denial of service
First Time appeared Eleveo
Eleveo quality Management
Weaknesses CWE-404
CPEs cpe:2.3:a:eleveo:quality_management:*:*:*:*:*:*:*:*
Vendors & Products Eleveo
Eleveo quality Management
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Eleveo Quality Management
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-04T04:00:12.008Z

Reserved: 2026-09-03T18:45:00.731Z

Link: CVE-2026-85407

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T05:17:15.587

Modified: 2026-09-04T05:17:15.587

Link: CVE-2026-85407

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T05:30:13Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release