CVE-2026-92805 is a missing-authentication vulnerability in UVdesk Community Skeleton through version 1.1.8. Installation-wizard endpoints handled by ConfigureHelpdesk controller actions do not require authentication and do not validate whether the application has already been installed. A remote unauthenticated attacker can submit crafted wizard requests to alter database configuration and create a super-administrator account.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This three-file repository contains an MIT license, a usage-focused README, and one standalone Python 3 exploit script using only the standard library. It targets CVE-2026-92805 in UVdesk Community Skeleton through 1.1.8: wizard XHR routes allegedly remain callable without authentication or an installation-state check after setup. The script maintains cookies, sends XMLHttpRequest-like headers, handles compressed responses, follows redirects while preserving selected POST requests, supports TLS-verification bypass, and can rebase its target URL after redirects. Its --test mode is a non-destructive endpoint fingerprint. Its --admin mode supplies database and administrator values through the wizard workflow, invokes configuration and migration routes, and provisions a super-admin, potentially redirecting the application's DATABASE_URL to an attacker-selected or newly created schema. No external exploitation framework, reverse shell, or OS command execution payload is present.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication and installation-state validation flaw in UVdesk Community Skeleton through version 1.1.8. Crafted unauthenticated requests to ConfigureHelpdesk wizard endpoints can change the database configuration and create super-administrator accounts, resulting in full instance compromise.
A critical missing-authentication vulnerability in UVdesk Community Skeleton through version 1.1.8 installation-wizard endpoints. Remote unauthenticated attackers can reconfigure the database and create super-administrator accounts, resulting in complete compromise of the affected instance.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.