Junglewise Threat Intelligence

CVE-2025-14600: vsDesk insecure deserialization and path traversal in configuration

CVE-2025-14600 · Severity: info · CVSS 9.3 · Published 2026-08-19

Technologies: vsDesk. Vendors: vsDesk.

Executive brief

vsDesk is a help desk and IT service management platform used by organizations to manage support requests and customer interactions. An insecure deserialization flaw allows remote attackers to bypass authentication and create administrative accounts by manipulating LDAP configuration files, effectively taking over the entire system.

Technical details

The vulnerability is an insecure deserialization flaw combined with a path traversal weakness in vsDesk's configuration file handling. An unauthenticated remote attacker can manipulate application configuration data, specifically LDAP configuration files, to force the system to authenticate against an attacker-controlled LDAP server and automatically provision a new administrative account. The root cause is insufficient validation when processing configuration file paths and contents. The attack requires network access to the application but no authentication or user interaction. The vendor patched this vulnerability in version 14.0402 and later by restricting configuration file selection to the configuration directory, validating file paths using realpath(), and making configuration content processing robust against malformed data.

Affected products

  • vsDesk vsDesk before 14.0402

Timeline

  • 2026-08-19: disclosed
  • 2026-04-21: patched: Patch released in version 14.0402 and later (release notes reference 14.0422)

References

Related threats