MEDIUMVulnerability

CVE-2026-72554

A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations belonging to other customers via the v1 REST API. The API verifies the existence of the requested ticket but not ownership, enabling any authenticated user to access arbitrary ticket threads including internal agent notes containing sensitive information.

Properties

severity
MEDIUM
score
6.5
epss_score
0.00334
cve_id
CVE-2026-72554
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
published_at
2026-08-11T12:17:41.103
last_modified
2026-09-03T17:51:18.670
epss_percentile
0.2612

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Access Control

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72554 — Ninja Signal Threat Intelligence | Ninja Signal