A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations belonging to other customers via the v1 REST API. The API verifies the existence of the requested ticket but not ownership, enabling any authenticated user to access arbitrary ticket threads including internal agent notes containing sensitive information.
References
| Link | Resource |
|---|---|
| https://github.com/ladybirdweb/faveo-helpdesk |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-11 12:17
Updated : 2026-09-03 17:51
NVD link : CVE-2026-72554
Mitre link : CVE-2026-72554
CVE.ORG link : CVE-2026-72554
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
