Junglewise Threat Intelligence

CVE-2023-30059: MK-Auth IDOR in support ticket management

CVE-2023-30059 · Severity: medium · CVSS 5.4 · Published 2026-05-12

Executive brief

MK-Auth is a management platform used by Internet Service Providers (ISPs) to manage client accounts and support requests. A security flaw allows an authenticated user to view or send support messages on behalf of other customers by simply changing a number in the web address. This could lead to the exposure of private customer communications and unauthorized modifications to technical support tickets.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the 'Chamados Técnicos' component of the MK-Auth Central panel. The application fails to properly validate if the authenticated user has permission to access the specific support ticket ID requested via the 'chamado' GET parameter in the URL 'central/suporte.hhvm?page=mensagens&chamado='. An attacker with valid low-privileged credentials can perform a horizontal privilege escalation by fuzzing or predicting the ticket ID (which follows a DDMMYY format followed by 8 digits). This allows the attacker to read private support messages and send unauthorized responses on behalf of other clients.

Affected products

  • MK-Auth MK-Auth 23.01K4.9

Timeline

  • 2026-05-12: disclosed: Initial CVE publication
  • 2026-05-12: advisory: Public disclosure via GitHub repository

References

Related threats