External risk intelligence

UVdesk Community Skeleton Unauthenticated Super Admin Creation

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-92805

The vulnerability exists in a helpdesk application framework's installation and configuration wizard endpoints. Helpdesk software is typically deployed as a web-based service intended to be accessible to users for support, making the web interface and associated configuration endpoints commonly reachable from the internet.

Missing Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects UVdesk Community Skeleton, a helpdesk application framework, allowing unauthenticated attackers to gain full control of an instance by repointing the database and creating super administrator accounts. The core issue lies in the failure to properly authenticate or validate the installation state on specific configuration wizard endpoints. While the main concern is confirming relevance and exposure, the potential for unauthorized access and data manipulation at a critical level is the primary risk.

  • Attackers can take over the helpdesk.
  • It impacts helpdesk software used externally.
  • Confirm if your helpdesk is affected.

Attack Path

How an attacker could exploit the issue

An attacker could target the UVdesk Community Skeleton's installation wizard, which lacks proper authentication and validation. By sending specially crafted requests to these wizard endpoints, an attacker can bypass security checks, redirect the database, and establish their own super administrator accounts, ultimately leading to complete control over the helpdesk instance.

  • No authentication required to access.
  • Submitting crafted requests to wizard endpoints.
  • Full control of the helpdesk instance.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to reconfigure the helpdesk system, including changing its database and creating new administrator accounts. This is possible when the installation wizard endpoints are accessible over the network.

  • Helpdesk system configuration and control.
  • Crafted requests to wizard endpoints.
  • Full instance takeover by attackers.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects the UVdesk Community Skeleton, likely managed by application owners and potentially the platform team responsible for the underlying infrastructure. The first practical move is to identify all instances of this software, confirm their exposure and business criticality, and then engage the accountable owner to plan remediation, which may involve coordination with the vendor if the software is third-party.

  • Application owners should manage this issue.
  • Verify instance reachability and business criticality.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is UVdesk Community Skeleton?

UVdesk Community Skeleton is an open-source framework designed for building helpdesk and customer support ticketing systems. It provides the core structure and routing logic necessary to manage customer inquiries and support workflows within a web-based environment.

How does CVE-2026-92805 work?

This vulnerability is classified as CWE-306, which refers to a missing authentication for a critical function. The application fails to verify if a user is authorized or if the installation is already complete when accessing specific setup wizard endpoints, allowing unauthorized actions.

What triggers the vulnerability in this CVE?

The issue is triggered when an attacker sends specifically formatted network requests directly to the application's installation wizard controllers. Simply browsing the main helpdesk portal or standard user-facing support pages does not trigger this flaw.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as a likely risk because helpdesk platforms are typically hosted as web services intended for public access. If your installation wizard endpoints remain reachable over the internet, the risk of unauthorized instance takeover increases.

How do I respond to this vulnerability?

First, locate all running instances of the software within your environment to determine which are active. Once identified, evaluate their reachability and prioritize those accessible from the internet. Coordinate with your application owners to plan remediation and restrict access to the wizard endpoints.

References