CVE-2025-71421

Summary

UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration.

Affected Software

VendorProductVersion RangeStatus
uvdeskcore-framework0 < 1.1.7affected
uvdeskcore-framework1.1.7unaffected
uvdeskcommunity-skeleton0 < 1.1.8affected
uvdeskcommunity-skeleton1.1.8unaffected

Weaknesses

  • CWE-269: Improper Privilege Management

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References