What is CVE-2026-72554?
CVE-2026-72554 is a broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3, allowing any self-registered customer to read other customers' ticket conversations via the v1 REST API. The API only verifies ticket existence, not ownership, exposing confidential data. Immediate update or implementation of ownership verification on the API is required.
Azərbaycanca: CVE-2026-72554, Ladybird Web Solution Faveo Helpdesk 2.0.3 versiyasında Broken Access Control zəifliyidir. Bu zəiflik, istənilən qeydiyyatdan keçmiş müştəriyə v1 REST API vasitəsilə digər müştərilərin ticket konfidensial söhbətlərini oxumağa imkan verir. Təcili olaraq proqramı ən son versiyaya yeniləmək və ya API səviyyəsində ticket sahibliyini yoxlayan əlavə giriş nəzarəti tətbiq etmək lazımdır.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What application does CVE-2026-72554 affect?
This vulnerability affects version 2.0.3 of Ladybird Web Solution's Faveo Helpdesk.
How does the CVE-2026-72554 broken access control lead to confidential data exposure?
The v1 REST API only verifies ticket existence, not ownership, allowing any self-registered customer to read other customers' confidential ticket conversations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.