CVE-2021-31929
Description
Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and settings, such as fraud prevention, coupon groups, email templates, or referrals.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Annex Cloud Loyalty Experience Platform before version 2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and settings, including fraud prevention, coupon groups, email templates, and referrals.
Vulnerability
Annex Cloud Loyalty Experience Platform versions prior to 2021.1.0.1 contain an access control vulnerability. Any authenticated user can modify loyalty campaigns and settings, such as fraud prevention, coupon groups, email templates, or referrals. The vulnerability exists in the platform's administrative functionality, where insufficient authorization checks allow authenticated users to perform modifications that should be restricted to higher-privileged roles.
Exploitation
An attacker needs valid credentials for any user account on the Annex Cloud Loyalty Experience Platform. With those credentials, the attacker can access the administrative interface and modify various loyalty program configurations, including fraud prevention rules, coupon groups, email templates, and referral settings. No additional privileges or user interaction is required beyond authentication.
Impact
Successful exploitation allows the attacker to alter critical loyalty program settings, potentially leading to unauthorized coupon generation, modification of email templates (which could be used for phishing), disabling fraud prevention measures, or manipulating referral programs. This could result in financial loss, reputational damage, and compromise of the loyalty platform's integrity.
Mitigation
The vulnerability is fixed in Annex Cloud Loyalty Experience Platform version 2021.1.0.1. Organizations should upgrade to this version or later. No workarounds are documented in the available references. If upgrading is not immediately possible, administrators should review and restrict user permissions to the minimum necessary.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Annex Cloud/Loyalty Experience Platformdescription
- Range: <2021.1.0.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.mdmitrex_refsource_MISC
- www.annexcloud.commitrex_refsource_MISC
News mentions
0No linked articles in our index yet.