Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 19 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access. By manipulating application configuration data, an attacker can force the system to authenticate against an arbitrary LDAP server and provision a new administrative account. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch. | |
| Title | Admin Account Takeover via Path Traversal in vsDesk | |
| Weaknesses | CWE-305 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Kaspersky
Published:
Updated: 2026-08-19T18:39:28.932Z
Reserved: 2025-12-12T18:40:38.416Z
Link: CVE-2025-14600
Updated: 2026-08-19T18:39:18.161Z
Status : Received
Published: 2026-08-19T18:16:30.270
Modified: 2026-08-19T19:17:08.623
Link: CVE-2025-14600
No data.
OpenCVE Enrichment
No data.
-
CWE-305
Authentication Bypass by Primary Weakness