← Back to search

CVE-2025-71421

7.2 HIGHpublic exploit available

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows agents with agent-management privilege to escalate their role to administrator, gaining full administrative control.
Exploitability
Exploitation requires an authenticated agent with specific privileges and direct manipulation of the role parameter.
Blast radius
If exploited, it could lead to complete system compromise affecting agents, tickets, and mail configurations.
Prioritized remediation
Update to UVdesk core-framework version 1.1.7 or later immediately.
privilege-escalationwebadmin-control

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-269

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.