CVE-2026-63082
MEDIUMPerfect Support Ticketing System 1.7 Broken Access Control via Agent Assignment
Title source: cnaDescription
Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the Support Agent assignment field of tickets by bypassing intended authorization checks. Attackers can add or remove any user, including Superadmin accounts, from the Support Agent field of any ticket to which they are assigned, circumventing role-based access controls.
References (2)
Core 2
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/aaronamran/CVE-Disclosures/blob/main/CVE-2026/CVE-2026-63082
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/perfect-support-ticketing-system-broken-access-control-via-agent-assignment
Scores
CVSS v3
5.4
EPSS
0.0015
EPSS Percentile
5.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (1)
Ultimate Fosters/Perfect Support Ticketing & Document Management System
< 1.7
Published
Jul 16, 2026
Tracked Since
Jul 16, 2026