CVE-2025-53118
Securden Unified PAM Authentication Bypass
Record summary
CVE-2025-53118 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 10, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 25, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Unified PAMBrowse Securden / Unified PAMDefault status: unaffected | VulnCheck, CVE List | 9.0.* to ≤ 11.3.1 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALSecurden Unified PAM - Authentication Bypass
An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.
Impact
Unauthenticated attackers can control administrator backup functions to compromise passwords, secrets, and application session tokens stored in Unified PAM.
Remediation
Upgrade Securden Unified PAM to the latest version that implements proper authentication checks on backup functions.
Source: ProjectDiscovery