Junglewise Threat Intelligence

CVE-2026-85407: Eleveo Quality Management denial of service via Conversation Handler

CVE-2026-85407 · Severity: medium · CVSS 4.3 · Published 2026-09-04

Technologies: Eleveo Quality Management. Vendors: Eleveo.

Executive brief

Eleveo Quality Management is a quality assurance and performance management platform used by contact centers and customer service operations. A flaw in the Conversation Handler component allows a remote attacker to trigger a denial of service by manipulating the labels parameter in API requests, potentially disrupting access to conversation data and analytics for legitimate users.

Technical details

The vulnerability exists in the Conversation Handler component's processing of the /enc-fwk-data/api/v3/conversations/<ID>/events endpoint. By manipulating the labels argument, an unauthenticated remote attacker can cause a denial of service condition. The attack requires network access to the affected API endpoint but no authentication or special preconditions. An exploit proof-of-concept has been publicly released. No vendor patch has been provided despite early disclosure notification.

Affected products

  • Eleveo Quality Management 9.7.0

Timeline

  • 2026-09-04: disclosed: Public disclosure with proof-of-concept

References

Related threats