Authorization Bypass in UVdesk Core Framework Affects Multiple Support Groups
CVE-2025-71420

5.3MEDIUM

Key Information:

Vendor

Uvdesk

Vendor
CVE Published:
21 September 2026

What is CVE-2025-71420?

The UVdesk core-framework prior to version 1.1.7 is vulnerable to an authorization bypass flaw that allows authenticated agents to gain unauthorized access to saved replies intended for other support groups. This vulnerability enables users with the ROLE_AGENT to enumerate saved reply identifiers, compromising the confidentiality of sensitive content that is meant for specific teams. As a result, organizations using vulnerable versions are at risk of exposing internal information across their support structures. Immediate updates to version 1.1.7 or later are recommended to mitigate this security threat.

Affected Version(s)

community-skeleton 0 < 1.1.8

core-framework 0 < 1.1.7

community-skeleton 1.1.8

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

leediay153
.