OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2025-71421 (CVSS 8.6)

NVD · officialPublished Sep 21, 2026Risk 37/100

UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration.

CVSS
8.6
AV:NetworkAC:LowPR:HighUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source