CVE-2025-71420: UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply

Published Sep 21, 2026
·
Updated

UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLEAGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not belong to.

Affected Software

1 affected component
Uvdesk core-framework<1.1.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade UVdesk core-framework to a version that resolves this vulnerability.

    Fixed in 1.1.7

Event History

Sep 21, 2026
CVE Published
via MITRE·01:43 PM
Data Sourced
via MITRE·01:43 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which users can exploit this issue?

An authenticated UVdesk user with the ROLE_AGENT role can exploit it. The issue affects agents who can reach the saved reply endpoint, including agents outside the support group or team to which a reply is restricted.

2

What information can be exposed?

An attacker can enumerate saved reply identifiers and read the content of saved replies restricted to other support groups or teams. The provided data indicates an information-disclosure impact, with no integrity or availability impact.

3

Are unauthenticated attackers affected?

No. Exploitation requires authentication and the ROLE_AGENT role; the supplied vector lists privileges as low and user interaction as not required.

4

What version resolves the issue?

Upgrade UVdesk core-framework to version 1.1.7 or later. Versions before 1.1.7 are identified as affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203