Access Control Flaw in BadChoice Handesk Affects Team Lead Data Management
CVE-2026-72563
8.1HIGH
What is CVE-2026-72563?
A vulnerability in BadChoice Handesk permits any authenticated agent to modify lead records belonging to other teams. This flaw arises from the LeadsController@update endpoint, which lacks proper authorization checks, allowing agents unrestricted access to overwrite sensitive data. Additionally, the Lead model’s parameters are set to an empty array, rendering all fields mass-assignable. Consequently, this oversight could enable malicious actors to manipulate or corrupt lead data across organizational boundaries.
Affected Version(s)
Handesk 0 <= 2026-07-10
