CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2026-105029: support-center-bundle 0 to before 1.1.3.3; +1 more affected products

CVE-2026-105029. CVSS 3.1 base score 4.3 (MEDIUM, Vendor/CNA). EPSS 0.002 (percentile 0.08926), scored 2026-10-05.

Affected technology

support-center-bundle · 0 to before 1.1.3.3
uvdesk

community-skeleton · 0 to before 1.1.8
uvdesk

Description’s affected range: before 1.1.3.3

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers. Vendor/CNA’s CVSS 4.0 assessment (base score 5.3/10) rates confidentiality and availability impact as none; integrity impact as low.

Published

CWE
CWE-639
CCR priority
17.2 /100 (P5)
CVSS 3.1
4.3 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N · Vendor/CNA
EPSS
0.002 · percentile 0.08926 · 2026-10-05
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-105029.html