Path Traversal Vulnerability in Faveo Helpdesk Disclosed

Path Traversal Vulnerability in Faveo Helpdesk Disclosed

First seen 26 Aug 2026, 07:53 UTC Feedlycve.threatint.comcvefeed.iovulners.com 57.1

Article Content

Browse articles
ThreatCluster

A path traversal vulnerability (CVE-2026-78435) has been identified in Faveo Helpdesk versions up to 2.0.3, affecting the unlink function in app/Http/Controllers/Admin/helpdesk/SettingsController.php. This vulnerability allows remote attackers to manipulate the data1 parameter, potentially deleting or modifying files outside the intended directory. The issue was reported to the project on August 24, 2026, but no response has been received from the maintainers. Although a patch was released on August 25, 2026, there is currently no evidence of public proof-of-concept exploits or active exploitation in the wild. Security professionals are advised to upgrade to versions beyond 2.0.3 and implement strict input validation. The CVSS score for this vulnerability is 4.0, indicating a medium severity level. The vulnerability has been disclosed publicly, raising concerns about its potential exploitation.

Key Points: • CVE-2026-78435 affects Faveo Helpdesk versions up to 2.0.3. • The vulnerability allows remote path traversal attacks via the unlink function. • A patch was released on August 25, 2026, following public disclosure.

Timeline

2026-08-24
CVE-2026-78435 published
The vulnerability was disclosed, affecting Faveo Helpdesk up to version 2.0.3.
cve.threatint.com
2026-08-25
Patch released
A patch for the vulnerability was made available on GitHub Advisory.
Feedly
2026-08-26
Public awareness raised
Multiple outlets reported on the vulnerability, emphasizing the need for immediate action.
cvefeed.io