{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/core-framework--1.1.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:uvdesk:core_framework:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2025-71421"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["core-framework (\u003c 1.1.7)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["UVdesk"],"content_html":"\u003cp\u003eUVdesk core-framework versions prior to 1.1.7 contain a critical improper privilege management vulnerability within the editAgent endpoint. This vulnerability allows an attacker who already possesses 'agent-management' privileges to escalate their own account role to 'ROLE_ADMIN'. By submitting a specifically crafted request to the editAgent API, an authenticated malicious agent can bypass internal access controls and modify their own authorization level. Successful exploitation grants the attacker full administrative control over the platform, including the ability to manage other agents, access sensitive ticket data, and modify mail server configurations. This flaw represents a significant risk to organizations relying on UVdesk for customer support operations, as it allows internal lateral movement and broad data access from a low-privileged account.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2025-71421 results in complete administrative compromise of the UVdesk helpdesk platform. Impacted organizations face unauthorized access to helpdesk tickets, potential exfiltration of customer data, and the ability for an attacker to modify mail configurations to intercept or redirect support communications.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch UVdesk core-framework to version 1.1.7 or later immediately to resolve the privilege escalation vulnerability associated with CVE-2025-71421.\u003c/li\u003e\n\u003cli\u003eAudit recent logs for the 'editAgent' endpoint to identify suspicious account modifications, specifically looking for users who have changed their own role status.\u003c/li\u003e\n\u003cli\u003eReview all existing administrator accounts within the UVdesk dashboard to identify and revert any unauthorized role changes performed by low-privileged agents.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-21T14:29:12Z","date_published":"2026-09-21T14:29:12Z","id":"https://feed.craftedsignal.io/briefs/2026-09-uvdesk-privilege-escalation/","summary":"An improper privilege management vulnerability in the UVdesk core-framework allows authenticated agents to escalate their privileges to administrator by manipulating the editAgent endpoint.","title":"Privilege Escalation in UVdesk core-framework","url":"https://feed.craftedsignal.io/briefs/2026-09-uvdesk-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Core-Framework (\u003c 1.1.7)","version":"https://jsonfeed.org/version/1.1"}