Junglewise Threat Intelligence

CVE-2025-71421: UVdesk core-framework privilege escalation in editAgent endpoint

CVE-2025-71421 · Severity: high · CVSS 7.2 · Published 2026-09-21

Technologies: UVdesk Core-Framework. Vendors: UVdesk.

Executive brief

UVdesk core-framework is a helpdesk platform that manages support tickets, agents, and customer communications. An agent with basic privileges can exploit the editAgent API endpoint to promote themselves to administrator, gaining full control over all agents, tickets, and email configuration. This allows a compromised or malicious agent account to take over the entire helpdesk system.

Technical details

The vulnerability is an improper privilege management flaw in the editAgent endpoint that fails to validate role escalation requests. An authenticated agent with agent-management privilege can submit their own account identifier with a role parameter set to ROLE_ADMIN to bypass authorization checks. The fix was released in version 1.1.8, which addressed the access privilege validation issue in the core-framework.

Affected products

  • UVdesk core-framework before 1.1.7

Timeline

  • 2026-09-21: disclosed
  • 2026-09-19: patched: Version 1.1.8 released with privilege validation fix

References

Related threats