Sceawere
Vulnerability Detail
CVE-2026-73350UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SupportCandy Broken Authentication Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 3h ago
- Vendor
- PSM Plugins
- Product
- SupportCandy
- Attack Type
- CWE-266 Incorrect Privilege Assignment
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-08-18T15:17:03.377Z",
"pubdate": "2026-08-18T15:17:03.377Z",
"executiveSummary": "An unauthenticated broken authentication vulnerability has been identified in the SupportCandy product, specifically affecting versions 3.5.1 and prior. This security flaw introduces critical risk implications by allowing unauthenticated malicious actors to bypass standard authentication mechanisms entirely. The vulnerability affects systems running the vulnerable versions of the SupportCandy plugin or software, exposing them to unauthorized access.\nThe inherent risk of this flaw is severe, as it grants external attackers the capability to interact with the application and potentially access sensitive ticketing data, administrative functions, or user accounts without possessing valid credentials. Exploitation requirements are minimal regarding authentication, as the flaw specifically resides in the unauthenticated attack surface of the affected software. Successful exploitation could lead to full compromise of confidentiality and integrity within the context of the support system, necessitating immediate attention from security administrators and system operators managing the affected instances.",
"technicalDetails": "The vulnerability is classified as a broken authentication flaw residing within the SupportCandy product across versions <= 3.5.1. The root cause stems from insufficient validation of user identity or improper implementation of authentication checks within the application's request handling logic for specific endpoints or functions. Network exposure is broad, as the affected components are typically reachable over standard HTTP/HTTPS protocols without requiring pre-existing session tokens or valid authorization headers.\nThe attack flow proceeds as follows: an unauthenticated attacker crafts a specialized HTTP request targeting the vulnerable endpoints within SupportCandy. Due to the absence of robust authentication verification, the application fails to validate whether the incoming request originates from a legitimate, authenticated session. Consequently, the backend processes the request and executes privileged operations or discloses restricted information intended solely for verified users. Privilege requirements are effectively non-existent for the initial request, allowing anonymous execution of actions that should normally be restricted.\nPayload behavior during exploitation typically involves bypassing login gates, interacting directly with underlying controller functions, or querying database records through exposed administrative or user-centric interfaces. Post-exploitation impact includes unauthorized data exposure, potential modification of support tickets, escalation of privileges if auxiliary vulnerabilities are chained, and complete subversion of access control policies enforced by the affected software."
}