CVE-2026-92805

Source
https://cve.org/CVERecord?id=CVE-2026-92805
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92805.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92805
Published
2026-09-16T20:32:54Z
Modified
2026-09-18T03:48:42Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard
Details

UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92805.json"
}
References

Affected packages

Git / github.com/uvdesk/community-skeleton

Affected ranges

Type
GIT
Repo
https://github.com/uvdesk/community-skeleton
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.1.8"
        },
        {
            "fixed": "1.1.8"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92805.json"