Executive brief
Eleveo Quality Management is a quality assurance and performance management platform used by contact centers and customer service operations. A flaw in the Conversation Handler component allows a remote attacker to trigger a denial of service by manipulating the labels parameter in API requests, potentially disrupting access to conversation data and analytics for legitimate users.
Technical details
The vulnerability exists in the Conversation Handler component's processing of the /enc-fwk-data/api/v3/conversations/<ID>/events endpoint. By manipulating the labels argument, an unauthenticated remote attacker can cause a denial of service condition. The attack requires network access to the affected API endpoint but no authentication or special preconditions. An exploit proof-of-concept has been publicly released. No vendor patch has been provided despite early disclosure notification.
Affected products
- Eleveo Quality Management 9.7.0
Timeline
- 2026-09-04: disclosed: Public disclosure with proof-of-concept