Improper Access Control in Live Helper Chat by Live Helper Chat
CVE-2026-44633
8.1HIGH
What is CVE-2026-44633?
Live Helper Chat, an open-source live support application, is prone to an improper access control vulnerability in version 4.84v. This flaw allows a REST user with permissions limited to 'lhchat/use' to update chat data in departments they lack access to. Specifically, the vulnerable REST API chat update endpoint accepts arbitrary fields, enabling unauthorized modifications to chat hashes and statuses. Consequently, this could lead to unauthorized access or manipulation of chat sessions through visitor or widget paths. Additionally, the same access can be exploited to set 'operation_admin', which may be executed as operator-side JavaScript, potentially further compromising security.
Affected Version(s)
livehelperchat < 4.84v
