Critical severity9.8NVD Advisory· Published Sep 16, 2026
CVE-2026-92805
CVE-2026-92805
Description
UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=1.1.8
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.