CVE-2025-61830

HIGH

Adobe Pass < 3.7.3 - Incorrect Authorization

Title source: llm
STIX 2.1

Description

Adobe Pass versions 3.7.3 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must install a malicious SDK.

References (1)

Core 1
Core References

Scores

CVSS v3 7.1
EPSS 0.0004
EPSS Percentile 11.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (2)
Adobe/Adobe Pass < 3.7.3
adobe/pass_authentication < 3.8.0
Published Nov 11, 2025
Tracked Since Feb 18, 2026