SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2025-14600

CRITICAL · CVSS 9.3 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An insecure deserialization vulnerability in vsDesk allows remote attackers to manipulate application configuration data, enabling unauthorized administrative access by authenticating against an arbitrary LDAP server. This critical flaw poses a significant risk to any organization using affected versions, as it can lead to the creation of new administrative accounts. Organizations should prioritize patching to versions 14.0402 and above to mitigate this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-14600
Severity
CRITICAL
CVSS
9.3
EPSS
0.37%

Original NVD Description

An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access. By manipulating application configuration data, an attacker can force the system to authenticate against an arbitrary LDAP server and provision a new administrative account. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.