CVE-2026-85408CWE-913CWE-915

CVE-2026-85408

Medium · published September 4, 2026

CVSS v3.1
4.3
EPSS
0%
Percentile
14.1
In the wild
Unconfirmed
What it is

A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. This manipulation of the argument createdBy causes dynamically-determined object attributes. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v4.0
5.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
EPSS
0.00233 · 14.1th percentile
Weaknesses
CWE-913 · Improper Control of Dynamically-Managed Code Resources; CWE-915 · Improperly Controlled Modification of Dynamically-Determined Object Attributes
Published
2026-09-04T09:17Z
References (5)
EPSS history
Timeline
  • 05 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 04 SEP 04:15Z
    Eleveo Quality Management Conversation events dynamically-determined object attributes
    cvelistv5