---
id: CVE-2026-92805
title: >-
  UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate
  installation state on wizard endpoints in ConfigureHelpdesk controller actions
summary: >-
  UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate
  installation state on wizard endpoints in ConfigureHelpdesk controller
  actions. Unauthenticated attackers can repoint the database and create super
  administrator a…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
vendor: uvdesk
product: community-skeleton
affected:
  - community-skeleton <= 1.1.8
published: '2026-09-16'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:43:58.793'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92805'
references:
  - url: 'https://github.com/uvdesk/community-skeleton'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/uvdesk/community-skeleton/blob/6f35040/src/Resources/config/routes.yaml#L1-L35
    label: disclosure@vulncheck.com
  - url: 'https://github.com/uvdesk/community-skeleton/issues/926'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/uvdesk-community-skeleton-through-1.1.8-missing-authentication-on-the-installation-wizard
    label: disclosure@vulncheck.com
tags:
  - nvd
  - exploit-available
  - cve.org
epss: 0.00641
epssPercentile: 0.48512
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/cflowsec/CVE-2026-92805'
  checkedAt: '2026-09-26T09:06:06.191Z'
exploitAvailable: true
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-19T01:50:03.711095Z'
ingestedAt: '2026-09-16T21:05:36.883Z'
---

## Overview

UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
