CVE-2025-14600
Admin Account Takeover via Path Traversal in vsDesk
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access. By manipulating application configuration data, an attacker can force the system to authenticate against an arbitrary LDAP server and provision a new administrative account. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.
| CWE | CWE-305 |
| Vendor | vsdesk |
| Product | vsdesk |
| Published | Aug 19, 2026 |
| Last Updated | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for vsdesk vsdesk
Be the first to know when new unknown vulnerabilities affecting vsdesk vsdesk are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
vsDesk / vsDesk
11.06.02 14.01.01
References
Credits
The vulnerability was discovered by Kirill Nikolaev from Kaspersky (https://kaspersky.com)