Sceawere

Vulnerability Detail

CVE-2026-103078UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JS Help Desk Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
10h ago
Vendor
Ahmad
Product
JS Help Desk
Attack Type
Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Authorization Bypass Through User-Controlled Key vulnerability in Ahmad JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through 4.0.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-05T09:17:06.137Z",
  "pubdate": "2026-10-05T09:17:06.137Z",
  "executiveSummary": "The JS Help Desk plugin for Ahmad JS Help Desk (versions up to and including 4.0.0) is susceptible to an Authorization Bypass vulnerability triggered by user-controlled keys. This flaw exists within the application's access control logic, allowing unauthorized actors to circumvent security restrictions.\nThe vulnerability stems from an incorrect configuration of access control security levels. By manipulating specific request keys, an attacker can escalate privileges or access restricted administrative functionality without the requisite credentials or authorization level.\nThe primary risk implication is the potential for complete unauthorized access to help desk data, system settings, and user management modules. An attacker can exploit this without prior authentication, provided they can successfully craft requests that manipulate the vulnerable key parameters. This vulnerability represents a critical security risk as it undermines the fundamental integrity of the application's role-based access control (RBAC) mechanisms.\nImpact includes potential data breaches, unauthorized modification of support tickets, and total compromise of help desk service operations. Immediate remediation is required to restore secure access control enforcement.",
  "technicalDetails": "The vulnerability is rooted in an Authorization Bypass Through User-Controlled Key mechanism located within the core request handling logic of the JS Help Desk plugin. In affected versions (up to and including 4.0.0), the application fails to adequately validate the server-side integrity of keys used to determine user authorization levels.\nThe root cause is an insecure implementation of access control checks where the application trusts client-supplied data (the 'user-controlled key') to verify if a user possesses the necessary privileges to perform a specific action. Instead of verifying session-based authorization or mapping the user's role against a static backend policy, the system relies on the presence and value of a key parameter included in the request payload or URL query string.\nExploitation occurs when an attacker identifies the specific key parameter used for authorization gating. By modifying or injecting this key into intercepted HTTP requests, the attacker can force the application to treat their session as having higher-level or administrative privileges. The application's backend function, responsible for enforcing security, blindly accepts this user-provided value, failing to cross-reference it with the server's session state or internal access control list (ACL).\nThe attack flow follows a predictable pattern: first, the attacker targets the plugin’s request handlers; second, they analyze the communication to identify the vulnerable key parameter; third, they craft a malicious payload containing the manipulated key to bypass the validation logic; finally, they gain unauthorized access to administrative functions or restricted resources. This flaw is particularly dangerous as it does not require a valid administrative session, only the ability to manipulate the request structure.\nBecause the vulnerability impacts the application’s core access control logic, any function gated by these keys is exposed. This includes, but is not limited to, ticket modification, user account management, and configuration changes within the JS Help Desk environment. The lack of robust, server-side validation means that even standard users or unauthenticated actors can effectively impersonate administrators, leading to full-scale unauthorized system exploitation."
}
CVE-2026-103078: JS Help Desk Authorization Bypass (MEDIUM Severity, CVSS: 4.3) | Sceawere