{"id":"CVE-2025-71421","title":"UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator","summary":"UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit the…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-269"],"vendor":"uvdesk","product":"core-framework","affected":["core-framework < 1.1.7","community-skeleton < 1.1.8"],"published":"2026-09-21","updated":"2026-09-22","sourceUpdated":"2026-09-22T20:43:58.793","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-71421","references":[{"url":"https://github.com/uvdesk/community-skeleton/releases/tag/v1.1.8","label":"disclosure@vulncheck.com"},{"url":"https://github.com/uvdesk/core-framework","label":"disclosure@vulncheck.com"},{"url":"https://github.com/uvdesk/core-framework/blob/v1.1.6/Controller/Account.php#L278-L282","label":"disclosure@vulncheck.com"},{"url":"https://github.com/uvdesk/core-framework/commit/b8bcdc503659f9d5c5cd73627cfc5d45508b9a55","label":"disclosure@vulncheck.com"},{"url":"https://github.com/uvdesk/core-framework/releases/tag/v1.1.7","label":"disclosure@vulncheck.com"},{"url":"https://hackmd.io/@leediay/B1Cz5voFGg","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/uvdesk-core-framework-before-1.1.7-privilege-escalation-via-editagent","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"epss":0.00441,"epssPercentile":0.37757,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-21T16:42:47.306954Z"},"ingestedAt":"2026-09-21T14:38:56.363Z","slug":"CVE-2025-71421","body":"## Overview\n\nUVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}