PT-2026-96099 · Uvdesk · Community-Skeleton+1

·

CVE-2025-71421

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE ADMIN to gain full administrative control over agents, tickets, and mail configuration.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71421

Affected Products

Community-Skeleton
Core-Framework