What is CVE-2026-18818?
An authorization bypass vulnerability has been identified in the `TicketDetailView` function within `apps/sspanel/views.py` of Ehco1996 django-sspanel, affecting versions up to 2023.12.26. This remote attack vector may allow unauthorized access to support ticket details. Users should immediately apply any vendor-provided updates as a mitigation.
Azərbaycanca: Ehco1996 django-sspanel proqramının 2023.12.26 versiyasına qədər olan versiyalarında `apps/sspanel/views.py` faylındakı `TicketDetailView` funksiyasında avtorizasiyadan yayınma zəifliyi aşkarlanıb. Bu, uzaqdan hücum edən şəxsə dəstək sorğularına icazəsiz giriş imkanı yarada bilər. İstifadəçilərə dərhal tərtibatçı tərəfindən buraxılacaq yeniləməni tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of django-sspanel are affected by CVE-2026-18818?
All versions of Ehco1996 django-sspanel up to 2023.12.26 are affected by this vulnerability.
What security issue does CVE-2026-18818 cause?
This authorization bypass vulnerability may allow a remote attacker to gain unauthorized access to support ticket details.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.