CVE-2026-105029
Received Received - Intake

Insecure Direct Object Reference in UVdesk Support Center Bundle

Vulnerability report for CVE-2026-105029, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: VulnCheck

Description

UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
uvdesk support-center-bundle to 1.1.3.3 (exc)
uvdesk community-skeleton to 1.1.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105029 is an Insecure Direct Object Reference (IDOR) vulnerability in UVdesk support-center-bundle versions before 1.1.3.3. It allows authenticated customers to rate tickets owned by other customers by supplying arbitrary ticket IDs without proper ownership verification. The vulnerability exists in the rateTicket action of Controller/Ticket.php.

Detection Guidance

To detect this vulnerability, check if your UVdesk support-center-bundle version is below 1.1.3.3. Use commands like 'composer show uvdesk/support-center-bundle' to verify the installed version. Monitor HTTP requests to the rateTicket endpoint for unauthorized ticket rating attempts by authenticated customers.

Impact Analysis

An attacker could manipulate ticket ratings by submitting requests for tickets they do not own. This could lead to unfair ratings, reputational damage, or skewed metrics for support teams. The impact is limited to authenticated customers who can submit or alter ratings on tickets they do not control.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves an IDOR flaw in ticket rating functionality rather than data breaches or unauthorized access to sensitive information. However, if ticket ratings or associated metadata contained personal data, improper access could indirectly impact compliance.

Mitigation Strategies

Immediately update the UVdesk support-center-bundle to version 1.1.3.3 or later. Apply the patch from the GitHub commit 3fa884a3adf0f317f354f83a1f9fa531234a551f which adds ownership checks before processing ticket ratings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105029. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart