Junglewise Threat Intelligence

CVE-2026-85408: Eleveo Quality Management object injection in Conversation Handler

CVE-2026-85408 · Severity: medium · CVSS 4.3 · Published 2026-09-04

Technologies: Eleveo Quality Management. Vendors: Eleveo.

Executive brief

Eleveo Quality Management is a call center quality assurance platform. A vulnerability in the conversation event API allows an attacker to manipulate object attributes through the createdBy parameter, potentially leading to unauthorized data modification or exposure without requiring authentication.

Technical details

The vulnerability is a dynamically-determined object attribute injection flaw in the Conversation Handler component, specifically in the /enc-fwk-data/api/v3/conversations/{ID}/events endpoint. An attacker can craft a request with a malicious createdBy parameter to inject or modify object attributes. The vulnerability is remotely exploitable and does not require authentication. An attacker can manipulate conversation event metadata and potentially access or modify sensitive quality management data. The vendor has not provided a patch despite early notification.

Affected products

  • Eleveo Quality Management 9.7.0

Timeline

  • 2026-09-04: disclosed: Publicly disclosed vulnerability

References

Related threats