Description
UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.
Published: 2026-09-16
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

UVdesk Community Skeleton through version 1.1.8 does not verify authentication or the installation state when handling wizard requests in the ConfigureHelpdesk controller. An attacker who can send HTTP requests to the wizard endpoints can change the database connection information and create a super‑administrator account, giving the attacker full control of the application. This flaw allows privilege escalation, enabling the attacker to create fully privileged administrative accounts. The weakness is a classic authentication bypass vulnerability (CWE-306).

Affected Systems

The affected product is UVdesk Community Skeleton version 1.1.8 or earlier. The vulnerability impacts installations that have not updated past this version, including private deployments on which the installation wizard remains exposed. The flaw resides in the ConfigureHelpdesk controller and the routes defined in the application's resources. No other known versions are affected according to the CNA data.

Risk and Exploitability

The flaw carries a CVSS score of 9.3, indicating critical severity. The EPSS score is listed as < 1%, implying a very low overall probability of exploitation as of the time of analysis, although the vulnerability remains potentially exploitable by anyone who can reach the wizard URLs. It is not included in the CISA KEV catalog. Attackers only need to interact with the web application’s wizard endpoints, which are typically accessible over HTTP or HTTPS without requiring prior authentication. If the sites expose these endpoints publicly, the attack can be performed remotely without any credentials. The exploit would involve posting a carefully crafted request to repoint the database and establish a new administrative account, granting unrestricted access.

Generated by OpenCVE AI on September 18, 2026 at 06:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade UVdesk Community Skeleton to a version newer than 1.1.8 where authentication checks have been added to the wizard routes.
  • If an immediate upgrade is not possible, disable or remove the wizard endpoints by adjusting the application’s routing configuration or by setting appropriate access controls so that only authenticated administrators can reach them.
  • Implement network‑level or web‑application firewall rules that block or restrict access to the wizard URLs (for example, blocking the /wizard path) until the patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 06:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.
Title UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard
First Time appeared Uvdesk
Uvdesk community-skeleton
Weaknesses CWE-306
CPEs cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*
Vendors & Products Uvdesk
Uvdesk community-skeleton
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Uvdesk Community-skeleton
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T01:52:49.216Z

Reserved: 2026-09-16T19:47:14.880Z

Link: CVE-2026-92805

cve-icon Vulnrichment

Updated: 2026-09-19T01:52:43.035Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:30.267

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-92805

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:15:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function