Junglewise Threat Intelligence

CVE-2026-63082: Ultimate Fosters Perfect Support Ticketing System broken access control

CVE-2026-63082 · Severity: medium · CVSS 5.4 · Published 2026-07-16

Executive brief

A vulnerability in the Perfect Support Ticketing & Document Management System allows staff members with 'Agent' privileges to modify who is assigned to a support ticket. This flaw enables an agent to add or remove any other user, including high-level administrators, from a ticket's assignment list. This could lead to unauthorized access to sensitive support information or the disruption of ticket management workflows by removing necessary oversight.

Technical details

A broken access control vulnerability (CWE-862) exists in the ticket assignment mechanism of Perfect Support Ticketing & Document Management System through version 1.7. The flaw allows a remote authenticated user with 'Agent' privileges to bypass authorization checks when modifying the 'Support Agent' field on tickets they are already assigned to. By interacting with the ticket management interface, an attacker can add or remove any user from the assignment list, including Superadmin accounts. This allows lower-privileged users to circumvent role-based access controls and alter the administrative assignment scope. No patch has been confirmed in the provided advisory.

Affected products

  • Ultimate Fosters Perfect Support Ticketing & Document Management System through 1.7

Timeline

  • 2026-07-16: advisory: NVD and VulnCheck published the vulnerability details.

References

Related threats