<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:uvdesk:core_framework:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3auvdeskcore_framework/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 21 Sep 2026 14:29:12 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3auvdeskcore_framework/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Privilege Escalation in UVdesk core-framework</title><link>https://feed.craftedsignal.io/briefs/2026-09-uvdesk-privilege-escalation/</link><pubDate>Mon, 21 Sep 2026 14:29:12 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-uvdesk-privilege-escalation/</guid><description>An improper privilege management vulnerability in the UVdesk core-framework allows authenticated agents to escalate their privileges to administrator by manipulating the editAgent endpoint.</description><content:encoded><![CDATA[<p>UVdesk core-framework versions prior to 1.1.7 contain a critical improper privilege management vulnerability within the editAgent endpoint. This vulnerability allows an attacker who already possesses 'agent-management' privileges to escalate their own account role to 'ROLE_ADMIN'. By submitting a specifically crafted request to the editAgent API, an authenticated malicious agent can bypass internal access controls and modify their own authorization level. Successful exploitation grants the attacker full administrative control over the platform, including the ability to manage other agents, access sensitive ticket data, and modify mail server configurations. This flaw represents a significant risk to organizations relying on UVdesk for customer support operations, as it allows internal lateral movement and broad data access from a low-privileged account.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2025-71421 results in complete administrative compromise of the UVdesk helpdesk platform. Impacted organizations face unauthorized access to helpdesk tickets, potential exfiltration of customer data, and the ability for an attacker to modify mail configurations to intercept or redirect support communications.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch UVdesk core-framework to version 1.1.7 or later immediately to resolve the privilege escalation vulnerability associated with CVE-2025-71421.</li>
<li>Audit recent logs for the 'editAgent' endpoint to identify suspicious account modifications, specifically looking for users who have changed their own role status.</li>
<li>Review all existing administrator accounts within the UVdesk dashboard to identify and revert any unauthorized role changes performed by low-privileged agents.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>