CVE WATCH / VULNERABILITY DETAIL
CVE-2026-102373
MEDIUMCVSS 6.5NVD feed
Published 29 September 2026 · tracked since 29 September 2026
Description
GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-102264 LOW 3.5
- CVE-2026-102263 MEDIUM 4.7
- CVE-2026-102414 LOW 3.7
- CVE-2026-102422 HIGH 8.1
- CVE-2026-102247 MEDIUM 6.8
- CVE-2026-96326 HIGH 7.2
- CVE-2026-101858 MEDIUM 4.7
- CVE-2026-101859 MEDIUM 5.4
- CVE-2026-101860 HIGH 8.8
- CVE-2026-101280 HIGH 7.3