CVE-2026-103078: Ahmad Js Help Desk

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Authorization Bypass Through User-Controlled Key vulnerability in Ahmad JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through 4.0.0.

Affected products

  • Ahmad Js Help Desk: up to and including 4.0.0

Published 2026-10-05. Last modified 2026-10-06.