← Back to CVEs
Perfect Support Ticketing & Document Management System

CVE-2026-63082 - Perfect Support Ticketing System 1.7 Broken Access Control via Agent Assignment

July 2026 — Common Vulnerabilities and Exposures (CVE)

A GitHub repository version of this disclosure can be read here: CVE-2026-63082.


DetailInformation
CVE RecordCVE-2026-63082
Severity5.3 Medium (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N)
5.4 Medium (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)
Date Published2026-07-17
Software NamePerfect Support Ticketing & Document Management System
Affected Version(s)0 through 1.7
Software Linkhttps://codecanyon.net/item/perfect-support-ticketing-document-management-system/32094844
VendorUltimate Fosters
Researcher CreditsAaron Amran Bin Amiruddin (@aaronamran), Shahrul Nizam Bin Shahrin

Description

Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the Support Agent assignment field of tickets by bypassing intended authorization checks. Attackers can add or remove any user, including Superadmin accounts, from the Support Agent field of any ticket to which they are assigned, circumventing role-based access controls.


Proof-of-Concept

1. As a prerequisite, ensure you are having access to an account with Agent privileges and an active support ticket is assigned to the target Agent (e.g., assigned by a Superadmin). Log in to the application using an account with Agent privileges.

CVE-2026-63082 Image 1

2. Open the assigned support ticket from the agent dashboard.

3. Locate the Support Agent assignment field on the ticket management interface. Notice that despite having lower privileges, the Agent has full modification rights over this field.

CVE-2026-63082 Image 2

4. Interact with the field to arbitrarily add or remove assigned users, including high-privileged Superadmin accounts, thereby breaking intended access controls and privilege boundaries.


Timeline



See you in the next hack.

@aaronamran

July 2026