community-skeleton vulnerability

UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.

Published 16 Sep 2026Updated 19 Sep 20264 sources
CVSS 9.3

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.