CVE-2026-85407CWE-404

CVE-2026-85407

Medium · published September 4, 2026

CVSS v3.1
4.3
EPSS
0%
Percentile
19.0
In the wild
Unconfirmed
What it is

A vulnerability was found in Eleveo Quality Management 9.7.0. This issue affects some unknown processing of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. The manipulation of the argument labels results in denial of service. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS v4.0
5.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
EPSS
0.00271 · 19.0th percentile
Weakness
CWE-404 · Improper Resource Shutdown or Release
Published
2026-09-04T09:17Z
References (5)
EPSS history
Timeline
  • 05 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 04 SEP 04:00Z
    Eleveo Quality Management Conversation events denial of service
    cvelistv5