CVE-2025-71421: UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent
UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLEADMIN to gain full administrative control over agents, tickets, and mail configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
UVdesk core-frameworkto a version that resolves this vulnerability.Fixed in 1.1.7Patch Privilege Escalation via editAgent
Event History
Frequently Asked Questions
Which accounts can exploit this issue?
An authenticated agent that already has the agent-management privilege can exploit it. The attacker does not need user interaction and can promote their own account to the administrator role.
What access does successful exploitation provide?
The attacker gains full administrative control over agents, tickets, and mail configuration.
Which versions require remediation?
UVdesk core-framework versions before 1.1.7 are affected. Upgrade to version 1.1.7 or later.
How can I check whether this may have been exploited?
Review agent role changes for unexpected promotions to ROLE_ADMIN, especially where an agent account promoted itself. Also review subsequent administrative changes involving agents, tickets, and mail configuration.