Authorization Bypass in Ehco1996 django-sspanel Affects Support Ticket Functionality
CVE-2026-18818

5.3MEDIUM

Key Information:

Vendor

Ehco1996

Vendor
CVE Published:
4 August 2026

What is CVE-2026-18818?

A vulnerability has been discovered in the Ehco1996 django-sspanel, specifically within the TicketDetailView function found in apps/sspanel/views.py. This weakness can allow attackers to perform unauthorized actions, potentially compromising the security of support ticket handling. The manipulation can occur remotely, making this a significant risk, especially for installations no longer actively maintained by the vendor. Despite understanding the implications, the vendor has not communicated any response regarding this concern, which amplifies the risk for current users.

Affected Version(s)

django-sspanel 2023.12.0

django-sspanel 2023.12.1

django-sspanel 2023.12.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

GalaxynX (VulDB User)
VulDB CNA Team
.