Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate saved reply identifiers and read content reserved for groups and teams they do not belong to. | |
| Title | UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply | |
| First Time appeared |
Uvdesk
Uvdesk community-skeleton |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Uvdesk
Uvdesk community-skeleton |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-21T14:14:06.582Z
Reserved: 2026-09-21T13:09:22.541Z
Link: CVE-2025-71420
Updated: 2026-09-21T14:13:52.710Z
Status : Received
Published: 2026-09-21T14:17:14.720
Modified: 2026-09-21T15:17:27.707
Link: CVE-2025-71420
No data.
OpenCVE Enrichment
No data.