CVE-2026-78434 | Faveo Helpdesk up to 2.0.3 post-ticket-reply Endpoint FormController.php post_ticket_reply missing authentication (Issue 8346)

SecurityVulns

A vulnerability identified as critical has been detected in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication.

This vulnerability is handled as CVE-2026-78434. The attack can be initiated remotely. Additionally, an exploit exists.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More