CVE-2025-71421
7.2 HIGHpublic exploit availablePublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows agents with agent-management privilege to escalate their role to administrator, gaining full administrative control.
- Exploitability
- Exploitation requires an authenticated agent with specific privileges and direct manipulation of the role parameter.
- Blast radius
- If exploited, it could lead to complete system compromise affecting agents, tickets, and mail configurations.
- Prioritized remediation
- Update to UVdesk core-framework version 1.1.7 or later immediately.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-269
Public exploit & PoC references
- https://github.com/uvdesk/community-skeleton/releases/tag/v1.1.8
- https://github.com/uvdesk/core-framework
- https://github.com/uvdesk/core-framework/blob/v1.1.6/Controller/Account.php#L278-L282
- https://github.com/uvdesk/core-framework/commit/b8bcdc503659f9d5c5cd73627cfc5d45508b9a55
- https://github.com/uvdesk/core-framework/releases/tag/v1.1.7
All references
- https://github.com/uvdesk/community-skeleton/releases/tag/v1.1.8
- https://github.com/uvdesk/core-framework
- https://github.com/uvdesk/core-framework/blob/v1.1.6/Controller/Account.php#L278-L282
- https://github.com/uvdesk/core-framework/commit/b8bcdc503659f9d5c5cd73627cfc5d45508b9a55
- https://github.com/uvdesk/core-framework/releases/tag/v1.1.7
- https://hackmd.io/@leediay/B1Cz5voFGg
- https://www.vulncheck.com/advisories/uvdesk-core-framework-before-1.1.7-privilege-escalation-via-editagent
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-61749PoC
- HIGHCVE-2026-94411PoC
- HIGHCVE-2026-18322
- HIGHCVE-2026-48826PoC
- CRITICALCVE-2025-29296
- MEDIUMCVE-2025-71419PoC
- MEDIUMCVE-2025-71420PoC
- CRITICALCVE-2026-0163
Related by shared AI tags and CWE weakness class. Browse the full archive.