What is CVE-2026-72563?
CVE-2026-72563 is a broken access control vulnerability in BadChoice Handesk as of 2026-07-10 that allows any authenticated agent to overwrite lead records of other teams via the LeadsController@update endpoint, due to a lack of authorization checks and an empty guarded array on the Lead model. Affected users should immediately implement access control mechanisms or apply any security patches released by the vendor.
Azərbaycanca: CVE-2026-72563 BadChoice Handesk platformunda aşkarlanan broken access control zəifliyidir. 10 iyul 2026-cı il tarixinə olan versiyada istənilən autentifikasiya olunmuş agent, LeadsController@update endpoint-i vasitəsilə digər komandalara məxsus lead qeydlərini üzərinə yaza bilər, çünki endpoint-də avtorizasiya yoxlaması aparılmır. Bu problemi aradan qaldırmaq üçün təcili olaraq endpoint-ə müvafiq giriş nəzarəti mexanizmləri əlavə edilməli və ya vendor tərəfindən buraxılan təhlükəsizlik yeniləməsi tətbiq olunmalıdır.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
In which platform was CVE-2026-72563 discovered?
CVE-2026-72563 was discovered in the BadChoice Handesk platform.
What can an authenticated agent do by exploiting this vulnerability?
Any authenticated agent can overwrite lead records of other teams via the LeadsController@update endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.