---
id: CVE-2026-105029
title: >-
  UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object
  reference vulnerability in the rateTicket action of Controller/Ticket.php that
  allows authenticated customers to rate other customers' tickets
summary: >-
  UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object
  reference vulnerability in the rateTicket action of Controller/Ticket.php that
  allows authenticated customers to rate other customers' tickets. Attackers can
  …
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-639
vendor: uvdesk
product: support-center-bundle
affected:
  - support-center-bundle < 1.1.3.3
  - community-skeleton < 1.1.8
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T00:16:36.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105029'
references:
  - url: 'https://github.com/uvdesk/support-center-bundle'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/uvdesk/support-center-bundle/commit/3fa884a3adf0f317f354f83a1f9fa531234a551f
    label: disclosure@vulncheck.com
  - url: 'https://hackmd.io/@leediay/idor-rate-ticket_uvdesk'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/uvdesk-support-center-bundle-before-1.1.3.3-idor-via-rateticket-ticket-rating-endpoint
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T23:34:57.408Z'
---

## Overview

UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
