No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 19 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance. | |
| Title | UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard | |
| First Time appeared |
Uvdesk
Uvdesk community-skeleton |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Uvdesk
Uvdesk community-skeleton |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-19T01:52:49.216Z
Reserved: 2026-09-16T19:47:14.880Z
Link: CVE-2026-92805
Updated: 2026-09-19T01:52:43.035Z
Status : Received
Published: 2026-09-16T21:17:30.267
Modified: 2026-09-19T02:16:54.940
Link: CVE-2026-92805
No data.
OpenCVE Enrichment
Updated: 2026-09-18T07:15:04Z