CVE-2025-71420
4.3 MEDIUMpublic exploit availablePublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows authenticated agents to access restricted saved replies, potentially exposing sensitive information across support groups.
- Exploitability
- Exploitation requires an authenticated agent role and knowledge of saved reply identifiers; moderate effort needed.
- Blast radius
- If exploited, it could lead to data leakage affecting multiple support groups and teams.
- Prioritized remediation
- Update to UVdesk core-framework version 1.1.7 or later to patch the authorization bypass vulnerability.
auth-bypasswebinfo-leakpatch-available
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not belong to.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weaknesses
CWE-639
Public exploit & PoC references
- https://github.com/uvdesk/community-skeleton/releases/tag/v1.1.8
- https://github.com/uvdesk/core-framework
- https://github.com/uvdesk/core-framework/blob/v1.1.6/Controller/TicketXHR.php#L838-L850
- https://github.com/uvdesk/core-framework/blob/v1.1.6/Services/TicketService.php#L1752-L1759
- https://github.com/uvdesk/core-framework/commit/de0422869708eb17a54bf6a98166abb80c0d483d
- https://github.com/uvdesk/core-framework/releases/tag/v1.1.7
All references
- https://github.com/uvdesk/community-skeleton/releases/tag/v1.1.8
- https://github.com/uvdesk/core-framework
- https://github.com/uvdesk/core-framework/blob/v1.1.6/Controller/TicketXHR.php#L838-L850
- https://github.com/uvdesk/core-framework/blob/v1.1.6/Services/TicketService.php#L1752-L1759
- https://github.com/uvdesk/core-framework/commit/de0422869708eb17a54bf6a98166abb80c0d483d
- https://github.com/uvdesk/core-framework/releases/tag/v1.1.7
- https://hackmd.io/@leediay/B1Cz5voFGg
- https://www.vulncheck.com/advisories/uvdesk-core-framework-before-1.1.7-authorization-bypass-via-saved-reply
- https://hackmd.io/@leediay/B1Cz5voFGg
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-52743PoC
- MEDIUMCVE-2026-94532PoC
- HIGHCVE-2026-94534PoC
- LOWCVE-2026-55060PoC
- HIGHCVE-2026-6639
- MEDIUMCVE-2026-70491PoC
- MEDIUMCVE-2026-75158PoC
- MEDIUMCVE-2026-94213
Related by shared AI tags and CWE weakness class. Browse the full archive.