CVE-2025-27702: Permissions bypass in the management console of Absolute Secure Access prior to version 13.54
CVE-2025-27702 is a vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly modify settings. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. There is no impact to system confidentiality or availability, impact to system integrity is high.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27702?
CVE-2025-27702 has a high severity rating due to the potential for attackers to improperly modify crucial settings.
How do I fix CVE-2025-27702?
To fix CVE-2025-27702, upgrade to Absolute Secure Access version 13.54 or later.
Who is affected by CVE-2025-27702?
CVE-2025-27702 affects users of Absolute Secure Access prior to version 13.54 who have administrative access.
What type of vulnerability is CVE-2025-27702?
CVE-2025-27702 is a permissions bypass vulnerability found in the management console.
Can administrative permissions be exploited in CVE-2025-27702?
Yes, CVE-2025-27702 allows attackers with administrative access to bypass assigned permissions.