MEDIUM
Ladybird Web Solution
CVE published 2026-08-11
CVE-2026-72554
A broken access control vulnerability in Faveo Helpdesk 2.0.3 allows self-registered customers to read ticket conversations of other customers via the v1 REST API. The API verifies ticket existence but not ownership, enabling authenticated users to access arbitrary ticket threads, including internal agent notes with sensitive information. Organizations should verify their inventory and apply vendor remedi [truncated]