CVE-2026-72595: CWE-284: Improper Access Control in BadChoice Handesk
A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket records belonging to other teams via the TicketsController@update endpoint. The endpoint calls no authorize() method and performs no team-scoped ownership check. An attacker with any agent account can modify, escalate, or corrupt tickets assigned to other teams.
AI Analysis
Technical Summary
This vulnerability in BadChoice Handesk arises from improper access control (CWE-284) in the TicketsController@update endpoint. The endpoint does not invoke any authorization method nor verify that the ticket belongs to the agent's team. Consequently, any authenticated agent can update tickets across teams, potentially modifying or escalating tickets they should not have access to. The CVSS 3.1 score is 8.1 (High), reflecting network attack vector, low attack complexity, required privileges of an authenticated agent, no user interaction, and high impact on confidentiality and integrity but no impact on availability. No patch or official remediation is currently documented, and no known exploits are reported in the wild.
Potential Impact
An attacker with any authenticated agent account can modify ticket records belonging to other teams, leading to unauthorized data modification, escalation of tickets, or corruption of ticket data. This compromises the confidentiality and integrity of ticket information across teams within the Handesk system. Availability is not affected. The vulnerability could disrupt normal ticket handling workflows and trust in the system's access controls.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict agent privileges to minimize exposure and monitor for unusual ticket update activities. Implement additional access control checks at the application level if possible.
CVE-2026-72595: CWE-284: Improper Access Control in BadChoice Handesk
Description
A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket records belonging to other teams via the TicketsController@update endpoint. The endpoint calls no authorize() method and performs no team-scoped ownership check. An attacker with any agent account can modify, escalate, or corrupt tickets assigned to other teams.
CVSS v3.1
Score 8.1high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in BadChoice Handesk arises from improper access control (CWE-284) in the TicketsController@update endpoint. The endpoint does not invoke any authorization method nor verify that the ticket belongs to the agent's team. Consequently, any authenticated agent can update tickets across teams, potentially modifying or escalating tickets they should not have access to. The CVSS 3.1 score is 8.1 (High), reflecting network attack vector, low attack complexity, required privileges of an authenticated agent, no user interaction, and high impact on confidentiality and integrity but no impact on availability. No patch or official remediation is currently documented, and no known exploits are reported in the wild.
Potential Impact
An attacker with any authenticated agent account can modify ticket records belonging to other teams, leading to unauthorized data modification, escalation of tickets, or corruption of ticket data. This compromises the confidentiality and integrity of ticket information across teams within the Handesk system. Availability is not affected. The vulnerability could disrupt normal ticket handling workflows and trust in the system's access controls.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict agent privileges to minimize exposure and monitor for unusual ticket update activities. Implement additional access control checks at the application level if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TuranSec
- Date Reserved
- 2026-08-10T10:33:03.257Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7b0705bf8831d539a0cc5a
Added to database: 08/11/2026, 11:27:01 UTC
Last enriched: 08/11/2026, 11:41:27 UTC
Last updated: 08/11/2026, 17:46:03 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.