CVE-2026-92805 PUBLISHED

UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard

Assigner: VulnCheck
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor uvdesk
Product community-skeleton
Versions Default: unaffected
  • affected from 0 to 1.1.8 (incl.)

Credits

  • George Chen finder

References

Problem Types

  • Missing Authentication for Critical Function CWE