CVE-2026-85408 Details
Description
A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. This manipulation of the argument createdBy causes dynamically-determined object attributes. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability exists in Eleveo Quality Management version 9.7.0 within the Conversation Handler component. The issue arises in an unknown function of the file '/enc-fwk-data/api/v3/conversations/<ID>/events', where the 'createdBy' argument can be manipulated. This manipulation leads to the creation of object attributes that are dynamically determined. The vulnerability can be exploited remotely, and the exploit has been publicly disclosed. Despite early contact with the vendor regarding this disclosure, there has been no response.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://drive.google.com/file/d/1fVUqrUoO29zkq2Ib_TXFNavX9yDo-Vp6/view?usp=sharing | [email protected] | ExploitPartial Content |
| https://vuldb.com/cve/CVE-2026-85408 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/894906 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/398558 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/398558/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-913 | Improper Control of Dynamically-Managed Code Resources | [email protected] |
| CWE-915 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Eleveo Quality Management | 9.7.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion