CVE-2026-85408: Eleveo Quality Management Conversation events dynamically-determined object attributes
A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. This manipulation of the argument createdBy causes dynamically-determined object attributes. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be performed remotely, but the CVSS vector indicates that low-level privileges are required. No user interaction is required.
What is the practical security impact?
The reported impact is limited to integrity, with no stated confidentiality or availability impact. The issue affects handling of the createdBy argument in the conversation events API endpoint.
Is there a known fix or vendor guidance?
No fix or vendor guidance is provided in the available information. The vendor was contacted about the disclosure but did not respond.
How urgent is remediation?
The issue is rated medium severity with a CVSS score of 4.3, but a public exploit disclosure exists and may be used. Prioritize it where low-privileged remote users can access the affected conversation events API.