Authorization Bypass in Ahmad JS Help Desk Plugin by Ahmad
CVE-2026-103078
4.3MEDIUM
What is CVE-2026-103078?
A vulnerability exists within the Ahmad JS Help Desk plugin, which allows an attacker to bypass authorization controls through a user-controlled key. This security flaw can lead to unauthorized access to sensitive information, affecting the proper functioning of access control security levels. The issue has been documented in version 4.0.0 of the plugin, emphasizing the need for immediate attention and remediation to safeguard user data.
Affected Version(s)
JS Help Desk 0 <= 4.0.0