{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3auvdeskcommunity_skeleton/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:uvdesk:community_skeleton:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-92805"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=AB910EDC-7848-5F2F-AEA9-EC3D6603C682\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Community Skeleton (\u003c= 1.1.8)"],"_cs_severities":["critical"],"_cs_tags":["web-application","authentication-bypass","critical-vulnerability"],"_cs_type":"advisory","_cs_vendors":["UVdesk"],"content_html":"\u003cp\u003eUVdesk Community Skeleton versions through 1.1.8 contain a critical authentication and validation vulnerability within the ConfigureHelpdesk controller's wizard endpoints. This flaw allows unauthenticated remote attackers to interact with the application installation wizard, which fails to verify whether the system is already configured. By submitting specially crafted HTTP requests to these endpoints, an attacker can redefine the database connection parameters and proceed to register a new super administrator account. This grants the attacker full administrative control over the helpdesk instance, enabling complete data exfiltration, service disruption, or further compromise of the underlying environment. Defenders should treat any unauthorized access to the application's wizard or installation pathways as a critical security incident.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants an attacker full administrative access to the helpdesk instance. Given the nature of helpdesk platforms, this results in unauthorized access to sensitive customer data, internal communication, and potentially privileged credentials stored within the system. The scale of impact includes complete loss of confidentiality, integrity, and availability for the affected instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade UVdesk Community Skeleton to a version beyond 1.1.8 as soon as a patch is available.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation or Web Application Firewall (WAF) rules to restrict access to installation/wizard routes (e.g., paths associated with ConfigureHelpdesk) to authorized management IPs only.\u003c/li\u003e\n\u003cli\u003eAudit existing administrator accounts for anomalous creations or changes following the announcement of this vulnerability.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for POST requests targeting wizard or installation configuration endpoints originating from external or unauthorized internal IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T18:11:20Z","date_published":"2026-09-16T21:51:47Z","id":"https://feed.craftedsignal.io/briefs/2026-09-uvdesk-skeleton-auth-bypass/","summary":"A vulnerability in UVdesk Community Skeleton versions through 1.1.8 allows unauthenticated attackers to reconfigure the database and create super administrator accounts via wizard endpoints.","title":"Unauthenticated Administrative Account Creation in UVdesk Community Skeleton","url":"https://feed.craftedsignal.io/briefs/2026-09-uvdesk-skeleton-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:uvdesk:community_skeleton:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}