Privilege Escalation in UVdesk Core-Framework by UVdesk
CVE-2025-71421

8.6HIGH

Key Information:

Vendor

Uvdesk

Vendor
CVE Published:
21 September 2026

What is CVE-2025-71421?

The UVdesk core-framework prior to version 1.1.7 is susceptible to a privilege escalation vulnerability found in the editAgent endpoint. This flaw enables agents with agent-management privileges to augment their role to administrator by submitting their account identifier with a manipulated role parameter. As a consequence, an attacker could gain unrestricted administrative control over agents, ticketing processes, and mail configurations, posing significant risks to the integrity of the system.

Affected Version(s)

community-skeleton 0 < 1.1.8

core-framework 0 < 1.1.7

community-skeleton 1.1.8

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

leediay153
.