What is CVE-2026-72595?
A broken access control vulnerability in BadChoice Handesk allows any authenticated agent to update ticket records belonging to other teams. The TicketsController@update endpoint lacks an authorization check and team-scoped ownership validation. It is recommended to immediately update Handesk to the latest version to mitigate this issue.
Azərbaycanca: BadChoice Handesk platformasında autentifikasiya olunmuş istənilən agentin digər komandalara məxsus ticket qeydlərini yeniləməsinə imkan verən qırıq giriş nəzarəti zəifliyi. TicketsController@update endpoint-i heç bir autorizasiya yoxlaması və komanda səviyyəsində sahiblik nəzarəti həyata keçirmir. Bu problemi aradan qaldırmaq üçün dərhal Handesk proqramını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What privileges does an attacker need to exploit the CVE-2026-72595 vulnerability?
To exploit this vulnerability, an attacker must have an account at any authenticated agent level within the BadChoice Handesk platform.
What measure is recommended to mitigate the CVE-2026-72595 vulnerability?
It is recommended to immediately update Handesk to the latest version to mitigate this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.