← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 24, 2026 · 22:17via CVEFeed

CVE-2026-78434 - Faveo Helpdesk post-ticket-reply Endpoint FormController.php post_ticket_reply missing authentication

Brief

CVE ID : CVE-2026-78434

Published : Aug. 24, 2026, 10:17 p. m.

  • 2 hours, 54 minutes ago

Description : A flaw has been found in Faveo Helpdesk up to 2.

  • 3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController. php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The exploit has been published and may be used.

The project was informed of the problem early through an issue report but has not responded yet.

Severity: 6.5

  • MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed