Junglewise Threat Intelligence

CVE-2026-72595: BadChoice Handesk broken access control in ticket updates

CVE-2026-72595 · Severity: high · CVSS 8.1 · Published 2026-08-11

Executive brief

BadChoice Handesk is a Laravel-based help desk and lead management application. A broken access control flaw allows any authenticated agent to view and modify ticket records belonging to other teams, potentially exposing customer information or allowing malicious ticket tampering that could disrupt service operations.

Technical details

The vulnerability is a broken access control issue in the TicketsController@update endpoint. The endpoint fails to invoke Laravel's authorize() method and performs no team-scoped ownership checks, allowing an authenticated agent to update tickets assigned to arbitrary teams. An attacker with any valid agent account can directly modify, escalate, or corrupt tickets outside their team's scope without authorization checks. No patch information is indicated in the advisory.

Affected products

  • BadChoice Handesk as of 2026-07-10

Timeline

  • 2026-08-11: disclosed

References

Related threats