LiveActive security incident?Get immediate response
CVE Record

CVE-2021-31928: Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to escalate privilege...

Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to escalate privileges to superadministrator. It was fixed in v2021.1.0.2.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

An authenticated user of Annex Cloud Loyalty Experience Platform could reportedly gain superadministrator privileges in versions before the fixed release. That is a serious governance risk because a low-privilege account could become a platform-wide administrator.

Executive priority

Treat this as high priority if the platform is used for customer loyalty operations. The business risk is unauthorized administrative control, but urgency depends on confirmed product use and version status.

Technical view

CVE-2021-31928 describes authenticated privilege escalation to superadministrator in Annex Cloud Loyalty Experience Platform before 2021.1.0.1. The CVE states it was fixed in version 2021.1.0.2. No CVSS, CWE, CPE, exploit mechanism, or configuration details are provided in the supplied sources.

Likely exposure

Organizations using Annex Cloud Loyalty Experience Platform versions before the fixed release may be exposed. The public record does not define exact CPEs, hosting model, vulnerable modules, or tenant-specific applicability.

Exploitation context

The source bundle does not show CISA KEV listing or any cited evidence of active exploitation. The only supported attack context is that exploitation requires an authenticated attacker.

Researcher notes

The public record is thin. It identifies product, privilege escalation impact, authentication requirement, and fixed version, but omits technical root cause, affected CPEs, CVSS, CWE, and exploit details.

Mitigation direction

  • Confirm whether Annex Cloud Loyalty Experience Platform is in use.
  • Verify the running version with Annex Cloud or internal platform owners.
  • Upgrade to version 2021.1.0.2 or later where applicable.
  • Review vendor guidance for any additional remediation requirements.
  • Audit privileged accounts and recent administrator changes.

Validation and detection

  • Inventory Annex Cloud deployments and service owners.
  • Confirm patch level is 2021.1.0.2 or later.
  • Review user roles for unexpected superadministrator assignments.
  • Check access logs for suspicious authenticated account activity.
  • Ask the vendor for tenant-specific exposure confirmation.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-31928 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.