CVE-2025-27702
MEDIUMAbsolute Secure Access < 13.54 - Authenticated Permission Bypass in Management Console
Title source: llmDescription
CVE-2025-27702 is a vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly modify settings. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. There is no impact to system confidentiality or availability, impact to system integrity is high.
References (1)
Core 1
Core References
Scores
CVSS v3
4.9
EPSS
0.0026
EPSS Percentile
17.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-284
Status
published
Products (1)
absolute/secure_access
< 13.54
Published
May 28, 2025
Tracked Since
Feb 18, 2026