CVE-2026-92805

critical

Description

UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.

References

https://www.vulncheck.com/advisories/uvdesk-community-skeleton-through-1.1.8-missing-authentication-on-the-installation-wizard

https://github.com/uvdesk/community-skeleton/issues/926

https://github.com/uvdesk/community-skeleton/blob/6f35040/src/Resources/config/routes.yaml#L1-L35

https://github.com/uvdesk/community-skeleton

Details

Source: Mitre, NVD

Published: 2026-09-16

Updated: 2026-09-19

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

CVSS v4

Base Score: 9.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: Critical

EPSS

EPSS: 0.00347