---
id: CVE-2025-71421
title: >-
  UVdesk core-framework before 1.1.7 contains an improper privilege management
  vulnerability in the editAgent endpoint that allows agents with
  agent-management privilege to escalate their own role to administrator
summary: >-
  UVdesk core-framework before 1.1.7 contains an improper privilege management
  vulnerability in the editAgent endpoint that allows agents with
  agent-management privilege to escalate their own role to administrator.
  Attackers can submit the…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
vendor: uvdesk
product: core-framework
affected:
  - core-framework < 1.1.7
  - community-skeleton < 1.1.8
published: '2026-09-21'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:43:58.793'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-71421'
references:
  - url: 'https://github.com/uvdesk/community-skeleton/releases/tag/v1.1.8'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/uvdesk/core-framework'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/uvdesk/core-framework/blob/v1.1.6/Controller/Account.php#L278-L282
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/uvdesk/core-framework/commit/b8bcdc503659f9d5c5cd73627cfc5d45508b9a55
    label: disclosure@vulncheck.com
  - url: 'https://github.com/uvdesk/core-framework/releases/tag/v1.1.7'
    label: disclosure@vulncheck.com
  - url: 'https://hackmd.io/@leediay/B1Cz5voFGg'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/uvdesk-core-framework-before-1.1.7-privilege-escalation-via-editagent
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00441
epssPercentile: 0.35676
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-21T16:42:47.306954Z'
ingestedAt: '2026-09-21T14:38:56.363Z'
---

## Overview

UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
