Skip to main content
Vulnerability Database/CVE-2026-92805

CVE-2026-92805: UVdesk Authentication Bypass Vulnerability

CVE-2026-92805 is an authentication bypass flaw in UVdesk Community Skeleton that lets attackers create admin accounts and control instances. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-92805 Overview

UVdesk Community Skeleton through version 1.1.8 contains a missing authentication vulnerability [CWE-306] in the ConfigureHelpdesk controller. The application fails to authenticate requests or validate installation state on wizard endpoints. Unauthenticated attackers can submit crafted requests to reach the installation wizard on a running instance. Successful exploitation lets attackers repoint the application database to an attacker-controlled server and create super administrator accounts. The result is full administrative control of the helpdesk instance, including access to tickets, customer data, and integrated mail credentials.

Critical Impact

Remote, unauthenticated attackers can take over UVdesk Community Skeleton instances by abusing exposed installation wizard endpoints to create super administrator accounts and repoint the database.

Affected Products

  • UVdesk Community Skeleton versions through 1.1.8
  • Deployments exposing the installation wizard routes defined in src/Resources/config/routes.yaml
  • Self-hosted UVdesk helpdesk instances derived from the community skeleton

Discovery Timeline

  • 2026-09-16 - CVE-2026-92805 published to NVD
  • 2026-09-16 - Last updated in NVD database

Technical Details for CVE-2026-92805

Vulnerability Analysis

UVdesk Community Skeleton is a Symfony-based helpdesk application. During initial deployment, an installation wizard configures the database connection and creates the first administrator account. The ConfigureHelpdesk controller exposes wizard endpoints via routes registered in src/Resources/config/routes.yaml.

The controller actions do not check whether installation has already completed and do not require authentication. As a result, the wizard remains reachable after the application is live. Any unauthenticated user who can reach the HTTP interface can invoke wizard actions that alter core configuration and account state.

An attacker who reaches these endpoints can submit a database configuration pointing to a server they control. The application accepts the new connection parameters and follows the wizard path for creating a super administrator account. The attacker then authenticates with the credentials they just supplied and gains full control of the application.

Root Cause

The root cause is missing authentication on privileged setup actions [CWE-306]. The controller trusts that wizard endpoints are only invoked during first-time setup but enforces no state check or authorization guard. Installation-time functionality remains exposed for the life of the deployment.

Attack Vector

Exploitation requires only network access to the affected instance. The attacker sends crafted HTTP requests to the wizard routes registered by the community skeleton. No credentials, user interaction, or prior access is required. The public VulnCheck advisory and GitHub issue #926 document the affected routes and behavior.

Detection Methods for CVE-2026-92805

Indicators of Compromise

  • Unexpected super administrator accounts appearing in the UVdesk user table after deployment
  • Application configuration files or environment variables referencing an external database host that was not provisioned by the operator
  • HTTP access log entries hitting installation wizard routes such as those under the ConfigureHelpdesk controller after the instance was already in service
  • Sudden loss of access to existing administrator accounts caused by a database swap

Detection Strategies

  • Review web server access logs for requests to installation wizard endpoints defined in src/Resources/config/routes.yaml and alert on any hits post-deployment
  • Baseline the application database connection string and alert on runtime changes to host, username, or database name
  • Audit the administrator account table on a schedule and flag accounts created outside change-control windows

Monitoring Recommendations

  • Forward UVdesk application and web server logs to a centralized logging platform for correlation with authentication and configuration events
  • Monitor outbound connections from the UVdesk host to unfamiliar database servers on ports such as 3306
  • Track file integrity on configuration files including .env and Symfony parameter files to detect wizard-driven modifications

How to Mitigate CVE-2026-92805

Immediate Actions Required

  • Restrict network access to UVdesk instances so that only trusted administrative networks can reach the application until a fixed release is deployed
  • Block external requests to installation wizard routes at the reverse proxy or web application firewall layer
  • Review administrator accounts and database configuration for signs of tampering and rotate credentials for any integrated services

Patch Information

No fixed version was listed in the NVD entry at publication. Track the UVdesk Community Skeleton repository and GitHub issue #926 for an official patch. Upgrade to a release later than 1.1.8 once the maintainers publish a fix that enforces authentication and installation-state checks on the ConfigureHelpdesk wizard actions.

Workarounds

  • Remove or comment out the wizard route definitions in src/Resources/config/routes.yaml after installation completes
  • Add reverse proxy rules that return HTTP 403 for any request path handled by installation wizard actions
  • Deploy the application behind a VPN or IP allowlist so untrusted networks cannot reach wizard endpoints
bash
# Example nginx block for installation wizard paths
location ~* ^/(install|configure|wizard) {
    deny all;
    return 403;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.