PT-2026-41019 · Unknown · Livehelperchat

·

CVE-2026-44633

·

Published

2026-05-14

·

Updated

2026-05-14

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Live Helper Chat version 4.84
Description The REST API chat update endpoint allows a user with lhchat/use permissions to update chats within departments they are not authorized to read. Because the endpoint accepts arbitrary chat object fields, an attacker can modify the chat hash and status to gain unauthorized access or tamper with the chat via visitor or widget paths. Additionally, this write primitive allows the modification of operation admin, which is subsequently executed as operator-side JavaScript.
Recommendations Update Live Helper Chat to a version newer than 4.84. Restrict access to the REST API chat update endpoint for users with lhchat/use permissions until the update is applied.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44633
GHSA-HJQQ-QMVJ-9WHM

Affected Products

Livehelperchat