Sceawere

Vulnerability Detail

CVE-2026-103079UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JS Help Desk Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
10h ago
Vendor
Ahmad
Product
JS Help Desk
Attack Type
Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Authorization Bypass Through User-Controlled Key vulnerability in Ahmad JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through 4.0.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-05T09:17:06.277Z",
  "pubdate": "2026-10-05T09:17:06.277Z",
  "executiveSummary": "The JS Help Desk plugin for Ahmad JS Help Desk is susceptible to an authorization bypass vulnerability stemming from user-controlled key handling. This security flaw allows unauthenticated or low-privileged users to manipulate access control parameters, resulting in the circumvention of established security levels. Impacted versions include JS Help Desk from n/a through 4.0.0. By exploiting this vulnerability, an attacker can gain unauthorized access to restricted help desk resources or administrative functions that should be gated by proper access control mechanisms. The risk implication is severe, as it undermines the integrity of the application's authorization framework. Successful exploitation requires the attacker to identify and manipulate specific keys used by the application for session or access validation, effectively escalating their privileges or bypassing internal permission checks. This flaw poses a significant threat to data confidentiality and administrative control within the help desk environment.",
  "technicalDetails": "The vulnerability resides within the application's access control logic, which relies on user-supplied keys to determine the authorization state of incoming requests. The root cause is the reliance on client-side input or improperly sanitized user-controlled keys for backend permission verification. When the application evaluates access requests, it fails to cryptographically verify or server-side validate the authenticity of the key presented by the user, effectively allowing for the injection of arbitrary values to bypass restriction checks.\nExploitation involves the manipulation of specific request parameters that the application utilizes to perform Authorization-as-a-Service (AaaS) checks. By injecting or altering the value of these user-controlled keys, an attacker can coerce the application into granting access to unauthorized modules, private tickets, or administrative configurations. Because the application logic incorrectly maps these keys to administrative security levels without verifying the user's role-based access control (RBAC) token, the server assumes the user possesses higher privileges than they are actually assigned.\nThe attack flow commences with the attacker identifying the parameters used by the plugin to handle access control tokens. Upon identifying the sensitive key, the attacker submits a modified request to the vulnerable endpoint, substituting a key or a manipulated value that maps to a higher privilege level or a bypassed authorization state. The vulnerable component, responsible for processing incoming help desk requests, then uses this malicious key to populate the session object or access context. Consequently, the application logic proceeds to process the request as if the user were authorized, successfully executing functions reserved for administrators.\nAffected versions are identified as ranging from n/a through 4.0.0. This flaw is inherent to the application's design regarding session and access management. The impact is significant, as it allows for the exfiltration of sensitive support ticket data, modification of help desk settings, or even administrative take-over. Because the system does not enforce strict server-side validation of the identity associated with the key, there is no effective mechanism currently in place to prevent the unauthorized elevation of privileges."
}
CVE-2026-103079: JS Help Desk Authorization Bypass (MEDIUM Severity, CVSS: 5.4) | Sceawere