<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>UVdesk - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/uvdesk/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 21:51:47 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/uvdesk/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Administrative Account Creation in UVdesk Community Skeleton</title><link>https://feed.craftedsignal.io/briefs/2026-09-uvdesk-skeleton-auth-bypass/</link><pubDate>Wed, 16 Sep 2026 21:51:47 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-uvdesk-skeleton-auth-bypass/</guid><description>A vulnerability in UVdesk Community Skeleton versions through 1.1.8 allows unauthenticated attackers to reconfigure the database and create super administrator accounts via wizard endpoints.</description><content:encoded><![CDATA[<p>UVdesk Community Skeleton versions through 1.1.8 contain a critical authentication and validation vulnerability within the ConfigureHelpdesk controller's wizard endpoints. This flaw allows unauthenticated remote attackers to interact with the application installation wizard, which fails to verify whether the system is already configured. By submitting specially crafted HTTP requests to these endpoints, an attacker can redefine the database connection parameters and proceed to register a new super administrator account. This grants the attacker full administrative control over the helpdesk instance, enabling complete data exfiltration, service disruption, or further compromise of the underlying environment. Defenders should treat any unauthorized access to the application's wizard or installation pathways as a critical security incident.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation grants an attacker full administrative access to the helpdesk instance. Given the nature of helpdesk platforms, this results in unauthorized access to sensitive customer data, internal communication, and potentially privileged credentials stored within the system. The scale of impact includes complete loss of confidentiality, integrity, and availability for the affected instance.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade UVdesk Community Skeleton to a version beyond 1.1.8 as soon as a patch is available.</li>
<li>Implement strict network segmentation or Web Application Firewall (WAF) rules to restrict access to installation/wizard routes (e.g., paths associated with ConfigureHelpdesk) to authorized management IPs only.</li>
<li>Audit existing administrator accounts for anomalous creations or changes following the announcement of this vulnerability.</li>
<li>Monitor webserver access logs for POST requests targeting wizard or installation configuration endpoints originating from external or unauthorized internal IP addresses.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>web-application</category><category>authentication-bypass</category><category>critical-vulnerability</category></item></channel></rss>