CVE-2021-31928
Description
Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to escalate privileges to superadministrator. It was fixed in v2021.1.0.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Annex Cloud Loyalty Experience Platform before 2021.1.0.2 allows any authenticated attacker to escalate privileges to superadministrator.
Vulnerability
Annex Cloud Loyalty Experience Platform prior to version 2021.1.0.1 contains an access control vulnerability that allows any authenticated attacker to escalate their privileges to the superadministrator role [1]. The issue is present in all versions before 2021.1.0.2, where the fix was implemented [1].
Exploitation
An attacker only needs a valid authenticated session on the platform—no additional privileges or special network position is required. The lack of proper privilege checks allows the attacker to perform actions that grant superadministrator access without any user interaction [1].
Impact
Upon successful exploitation, the attacker gains full superadministrator privileges, which provides unrestricted access to all platform features, configurations, and data. This leads to complete compromise of confidentiality, integrity, and availability of the loyalty experience platform [1].
Mitigation
The vulnerability is fixed in version 2021.1.0.2 [1]. All users should upgrade to this version or later. No workarounds are documented in the available references [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Annex Cloud/Loyalty Experience Platformdescription
- Range: <2021.1.0.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.mdmitrex_refsource_MISC
- www.annexcloud.commitrex_refsource_MISC
News mentions
0No linked articles in our index yet.