Improper Access Control in Live Helper Chat by Live Helper Chat
CVE-2026-44633

8.1HIGH

Key Information:

Vendor
CVE Published:
14 May 2026

What is CVE-2026-44633?

Live Helper Chat, an open-source live support application, is prone to an improper access control vulnerability in version 4.84v. This flaw allows a REST user with permissions limited to 'lhchat/use' to update chat data in departments they lack access to. Specifically, the vulnerable REST API chat update endpoint accepts arbitrary fields, enabling unauthorized modifications to chat hashes and statuses. Consequently, this could lead to unauthorized access or manipulation of chat sessions through visitor or widget paths. Additionally, the same access can be exploited to set 'operation_admin', which may be executed as operator-side JavaScript, potentially further compromising security.

Affected Version(s)

livehelperchat < 4.84v

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.