An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and other unspecified impacts. NOTE: As of April 2026, the vendor has officially decommissioned the affected legacy endpoints and associated services. The vulnerability is mitigated as the functional logic is no longer operational and the URLs have been removed from production.
References
| Link | Resource |
|---|---|
| https://github.com/viperbluff/Novastar-VNNOX-iCare-Privilege-Escalation | Exploit Third Party Advisory |
| https://security.novaicare.com/advisory-cve-2021-38289.html | |
| https://twitter.com/viperbluff/status/1439941380244230150?s=20&t=iPSn8eNxaxUKis5OKSQJRQ | Exploit Third Party Advisory |
| https://github.com/viperbluff/Novastar-VNNOX-iCare-Privilege-Escalation | Exploit Third Party Advisory |
| https://twitter.com/viperbluff/status/1439941380244230150?s=20&t=iPSn8eNxaxUKis5OKSQJRQ | Exploit Third Party Advisory |
Configurations
History
07 Apr 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Summary | (en) An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and other unspecified impacts. NOTE: As of April 2026, the vendor has officially decommissioned the affected legacy endpoints and associated services. The vulnerability is mitigated as the functional logic is no longer operational and the URLs have been removed from production. |
21 Nov 2024, 06:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/viperbluff/Novastar-VNNOX-iCare-Privilege-Escalation - Exploit, Third Party Advisory | |
| References | () https://twitter.com/viperbluff/status/1439941380244230150?s=20&t=iPSn8eNxaxUKis5OKSQJRQ - Exploit, Third Party Advisory |
Information
Published : 2022-07-12 14:15
Updated : 2026-04-07 17:16
NVD link : CVE-2021-38289
Mitre link : CVE-2021-38289
CVE.ORG link : CVE-2021-38289
JSON object : View
Products Affected
novastar
- novaicare
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
