← Back to search

CVE-2025-71420

4.3 MEDIUMpublic exploit available

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows authenticated agents to access restricted saved replies, potentially exposing sensitive information across support groups.
Exploitability
Exploitation requires an authenticated agent role and knowledge of saved reply identifiers; moderate effort needed.
Blast radius
If exploited, it could lead to data leakage affecting multiple support groups and teams.
Prioritized remediation
Update to UVdesk core-framework version 1.1.7 or later to patch the authorization bypass vulnerability.
auth-bypasswebinfo-leakpatch-available

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not belong to.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CWE-639

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.