PT-2026-94079 · Unknown · Uvdesk Community Skeleton

·

CVE-2026-92805

·

Published

2026-09-16

·

Updated

2026-09-25

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UVdesk Community Skeleton versions prior to 1.1.9
Description The software fails to authenticate or validate the installation state on wizard endpoints within the ConfigureHelpdesk controller actions. This allows unauthenticated attackers to repoint the database and create super administrator accounts by submitting crafted requests to these wizard endpoints, resulting in full control of the instance.
Recommendations Update UVdesk Community Skeleton to version 1.1.9 or later.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92805

Affected Products

Uvdesk Community Skeleton