VYPR
Unrated severityNVD Advisory· Published Jun 10, 2021· Updated Aug 3, 2024

CVE-2021-31928

CVE-2021-31928

Description

Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to escalate privileges to superadministrator. It was fixed in v2021.1.0.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Annex Cloud Loyalty Experience Platform before 2021.1.0.2 allows any authenticated attacker to escalate privileges to superadministrator.

Vulnerability

Annex Cloud Loyalty Experience Platform prior to version 2021.1.0.1 contains an access control vulnerability that allows any authenticated attacker to escalate their privileges to the superadministrator role [1]. The issue is present in all versions before 2021.1.0.2, where the fix was implemented [1].

Exploitation

An attacker only needs a valid authenticated session on the platform—no additional privileges or special network position is required. The lack of proper privilege checks allows the attacker to perform actions that grant superadministrator access without any user interaction [1].

Impact

Upon successful exploitation, the attacker gains full superadministrator privileges, which provides unrestricted access to all platform features, configurations, and data. This leads to complete compromise of confidentiality, integrity, and availability of the loyalty experience platform [1].

Mitigation

The vulnerability is fixed in version 2021.1.0.2 [1]. All users should upgrade to this version or later. No workarounds are documented in the available references [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.