CVE-2026-18818
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
Summary
A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views.py of the component Support Ticket Handler. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Ehco1996 | django-sspanel | 2023.12.0 | affected |
| Ehco1996 | django-sspanel | 2023.12.1 | affected |
| Ehco1996 | django-sspanel | 2023.12.2 | affected |
| Ehco1996 | django-sspanel | 2023.12.3 | affected |
| Ehco1996 | django-sspanel | 2023.12.4 | affected |
| Ehco1996 | django-sspanel | 2023.12.5 | affected |
| Ehco1996 | django-sspanel | 2023.12.6 | affected |
| Ehco1996 | django-sspanel | 2023.12.7 | affected |
| Ehco1996 | django-sspanel | 2023.12.8 | affected |
| Ehco1996 | django-sspanel | 2023.12.9 | affected |
| Ehco1996 | django-sspanel | 2023.12.10 | affected |
| Ehco1996 | django-sspanel | 2023.12.11 | affected |
| Ehco1996 | django-sspanel | 2023.12.12 | affected |
| Ehco1996 | django-sspanel | 2023.12.13 | affected |
| Ehco1996 | django-sspanel | 2023.12.14 | affected |
| Ehco1996 | django-sspanel | 2023.12.15 | affected |
| Ehco1996 | django-sspanel | 2023.12.16 | affected |
| Ehco1996 | django-sspanel | 2023.12.17 | affected |
| Ehco1996 | django-sspanel | 2023.12.18 | affected |
| Ehco1996 | django-sspanel | 2023.12.19 | affected |
| Ehco1996 | django-sspanel | 2023.12.20 | affected |
| Ehco1996 | django-sspanel | 2023.12.21 | affected |
| Ehco1996 | django-sspanel | 2023.12.22 | affected |
| Ehco1996 | django-sspanel | 2023.12.23 | affected |
| Ehco1996 | django-sspanel | 2023.12.24 | affected |
| Ehco1996 | django-sspanel | 2023.12.25 | affected |
| Ehco1996 | django-sspanel | 2023.12.26 | affected |
Weaknesses
- CWE-639: Authorization Bypass
- CWE-285: Improper Authorization
References
- https://vuldb.com/vuln/385817
- https://vuldb.com/vuln/385817/cti
- https://vuldb.com/cve/CVE-2026-18818
- https://vuldb.com/submit/857943
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.