PT-2026-78540 · Vsdesk · Vsdesk

·

CVE-2025-14600

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions vsDesk versions prior to 14.0402
Description An insecure deserialization issue allows a remote attacker to obtain unauthorized administrative access. By manipulating application configuration data, an attacker can force the system to authenticate against an arbitrary LDAP server and provision a new administrative account. Insecure deserialization occurs when untrusted data is used to abuse the logic of an application to execute arbitrary code or manipulate system behavior.
Recommendations Update to version 14.0402 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-14600

Affected Products

Vsdesk