Executive brief
BadChoice Handesk is a Laravel-based help desk and lead management application. A broken access control flaw allows any authenticated agent to view and modify ticket records belonging to other teams, potentially exposing customer information or allowing malicious ticket tampering that could disrupt service operations.
Technical details
The vulnerability is a broken access control issue in the TicketsController@update endpoint. The endpoint fails to invoke Laravel's authorize() method and performs no team-scoped ownership checks, allowing an authenticated agent to update tickets assigned to arbitrary teams. An attacker with any valid agent account can directly modify, escalate, or corrupt tickets outside their team's scope without authorization checks. No patch information is indicated in the advisory.
Affected products
- BadChoice Handesk as of 2026-07-10
Timeline
- 2026-08-11: disclosed