CVE-2026-92805: UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard
UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to unauthenticated takeover?
UVdesk Community Skeleton versions through 1.1.8 are affected where the installation wizard endpoints in the ConfigureHelpdesk controller are reachable. No attacker account or user interaction is required.
What can an attacker do through the affected wizard endpoints?
An attacker can submit crafted requests to repoint the database and create a super administrator account. This can give the attacker full control of the UVdesk instance.
How can I determine whether an instance may be affected?
Check whether the deployment uses UVdesk Community Skeleton version 1.1.8 or earlier and whether its ConfigureHelpdesk installation wizard routes are accessible. The issue is caused by those endpoints not authenticating requests or validating installation state.