OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2025-71421

HIGH · CVSS 7.2 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The vulnerability in the UVdesk core framework allows agents with management privileges to escalate their own roles to administrator via the editAgent endpoint. This improper privilege management can lead to unauthorized access and control over critical system components, including agents, tickets, and mail configurations. Organizations using UVdesk should prioritize patching this issue to prevent potential exploitation and ensure the integrity of their systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-71421
Severity
HIGH
CVSS
7.2
EPSS
0.44%

Original NVD Description

UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration.