Description
UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not belong to.
Published: 2026-09-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Patch
AI Analysis

Impact

UVdesk core‑framework versions prior to 1.1.7 expose an authorization bypass in the saved reply endpoint. Authenticated agents with the ROLE_AGENT permission can enumerate saved reply identifiers and retrieve content that is ostensibly restricted to other support groups or teams. The ability to read these replies effectively lifts the intended access controls, allowing agents to access information they should not see. The vulnerability is a classic example of improper authorization enforcement, as indicated by its CWE-639 classification.

Affected Systems

The vulnerability affects the UVdesk community skeleton and core framework products, specifically all releases before 1.1.7. Users deploying version 1.1.6 or earlier of the core framework and community skeleton are at risk. Patch version 1.1.7 or later removes the flaw.

Risk and Exploitability

The CVSS score of 5.3 places the issue in the medium severity range, and the EPSS score is not available, indicating no publicly known prevalence at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Exploit requires an authenticated agent account with ROLE_AGENT; therefore, attack is likely confined to environments where such credentials are already available or have been compromised. An attacker could enumerate all saved reply IDs through the endpoint and harvest content across support groups, thereby breaching confidentiality of group‑specific communications.

Generated by OpenCVE AI on September 21, 2026 at 15:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the UVdesk core framework to version 1.1.7 or later
  • Ensure that users assigned the ROLE_AGENT role only have permissions for their own support groups
  • If immediate upgrade is not feasible, restrict or remove the ROLE_AGENT privilege from users who do not require it until a patch is applied

Generated by OpenCVE AI on September 21, 2026 at 15:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Uvdesk core-framework
Vendors & Products Uvdesk core-framework

Mon, 21 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not belong to.
Title UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply
First Time appeared Uvdesk
Uvdesk community-skeleton
Weaknesses CWE-639
CPEs cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*
Vendors & Products Uvdesk
Uvdesk community-skeleton
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Uvdesk Community-skeleton Core-framework
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-06T13:36:46.572Z

Reserved: 2026-09-21T13:09:22.541Z

Link: CVE-2025-71420

cve-icon Vulnrichment

Updated: 2026-09-21T14:13:52.710Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T14:17:14.720

Modified: 2026-09-22T20:43:58.793

Link: CVE-2025-71420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:23:51Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key