PatchSiren

vsDesk CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM vsDesk CVE published 2026-08-20

CVE-2025-14602

The vsDesk application, specifically versions prior to 14.0101, contains a vulnerability that allows remote attackers to predict or brute-force uploaded file names due to a weak naming convention based on request timestamps. This issue can lead to unauthorized file access. Organizations using vsDesk should be aware of the potential risks and take immediate action to patch or mitigate the vulnerability. Th [truncated]