๐Ÿ” CVE Alert

CVE-2026-27954

UNKNOWN 0.0

LiveHelperChat has department-level authorization bypass in holdaction, blockuser, and transferchat endpoints

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints (holdaction.php, blockuser.php, and transferchat.php) load chat objects by ID without calling `erLhcoreClassChat::hasAccessToRead()`, allowing operators to act on chats in departments they are not assigned to. Operators with the relevant role permissions (holduse, allowblockusers, allowtransfer) can hold, block users from, or transfer chats in departments they are not assigned to. This is a horizontal privilege escalation within one organization. As of time of publication, no known patched versions are available.

CWE CWE-862
Vendor livehelperchat
Product livehelperchat
Published Feb 26, 2026
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for livehelperchat livehelperchat

Be the first to know when new unknown vulnerabilities affecting livehelperchat livehelperchat are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

LiveHelperChat / livehelperchat
<= 4.52

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/LiveHelperChat/livehelperchat/security/advisories/GHSA-87wc-2p86-h3w7