Skip to content
Threat Feed
critical advisory PoC updated

Unauthenticated Administrative Account Creation in UVdesk Community Skeleton

A vulnerability in UVdesk Community Skeleton versions through 1.1.8 allows unauthenticated attackers to reconfigure the database and create super administrator accounts via wizard endpoints.

CVE search metadata

CVE search record: CVE-2026-92805. Severity: critical. CVSS: 9.8. KEV: no. Product: Community Skeleton (<= 1.1.8). Brief: Unauthenticated Administrative Account Creation in UVdesk Community Skeleton. Brief link: https://feed.craftedsignal.io/briefs/2026-09-uvdesk-skeleton-auth-bypass/

What's new

  • 1. poc_available; added CVE-2026-92805 Sep 17, 18:11 via sploitus

UVdesk Community Skeleton versions through 1.1.8 contain a critical authentication and validation vulnerability within the ConfigureHelpdesk controller's wizard endpoints. This flaw allows unauthenticated remote attackers to interact with the application installation wizard, which fails to verify whether the system is already configured. By submitting specially crafted HTTP requests to these endpoints, an attacker can redefine the database connection parameters and proceed to register a new super administrator account. This grants the attacker full administrative control over the helpdesk instance, enabling complete data exfiltration, service disruption, or further compromise of the underlying environment. Defenders should treat any unauthorized access to the application's wizard or installation pathways as a critical security incident.

Impact

Successful exploitation grants an attacker full administrative access to the helpdesk instance. Given the nature of helpdesk platforms, this results in unauthorized access to sensitive customer data, internal communication, and potentially privileged credentials stored within the system. The scale of impact includes complete loss of confidentiality, integrity, and availability for the affected instance.

Recommendation

  • Upgrade UVdesk Community Skeleton to a version beyond 1.1.8 as soon as a patch is available.
  • Implement strict network segmentation or Web Application Firewall (WAF) rules to restrict access to installation/wizard routes (e.g., paths associated with ConfigureHelpdesk) to authorized management IPs only.
  • Audit existing administrator accounts for anomalous creations or changes following the announcement of this vulnerability.
  • Monitor webserver access logs for POST requests targeting wizard or installation configuration endpoints originating from external or unauthorized internal IP addresses.

Immediate actions

Restrict network access to installation wizard paths for all public-facing UVdesk instances.

IT Operations 24h

Mitigations

Upgrade UVdesk Community Skeleton to a version greater than 1.1.8 once vendor updates are released.

immediate IT Operations

CVE-2026-92805