Skip to content
CVE-2026-78435 - Exploits & Severity

CVE-2026-78435 - Exploits & Severity

Feedly August 25, 2026

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

A path traversal vulnerability exists in the Logo Handler component of Faveo Helpdesk up to version 2.0.3. The vulnerability is in the unlink function of app/Http/Controllers/Admin/helpdesk/SettingsController.php, where the data1 parameter is not properly validated, allowing path traversal attacks.

An authenticated administrative user can remotely manipulate file paths through the data1 parameter to delete or modify files outside the intended directory and potentially disrupt service availability.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

A patch is available via Github Advisory (GHSA-gcqg-5pvv-vcwv), added on 2026-08-25.

Upgrade Faveo Helpdesk to a version later than 2.0.3. Implement strict input validation and sanitization for the data1 parameter in the Logo Handler component. Restrict file operation permissions to only intended directories. Apply the available patch from the Github Advisory immediately given the public disclosure of this exploit.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Feedly found the first article mentioning CVE-2026-78435 . See article

NVD published the first details for CVE-2026-78435

A CVSS base score of 3.8 has been assigned.

GitHub Advisories released a security advisory .

Faveo Helpdesk Logo SettingsController.php unlink path traversalA vulnerabili...

CVE-2026-78435 - Faveo Helpdesk Logo SettingsController.php unlink path traversal CVE ID : CVE-2026-78435 Published : Aug. 24, 2026, 9:45 p.m. | 19 minutes ago Description : A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of ...

CVE-2026-78435 - Faveo Helpdesk Logo SettingsController.php unlink path traversal

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities

CWE Weaknesses (1)

Platforms (1)

Vulnerabilities (1)