CVE-2025-27703 is a privilege escalation vulnerability in the management
console of Absolute Secure Access prior to version 13.54. Attackers
with administrative access to a specific subset of privileged features
in the console can elevate their permissions to access additional
features in the console. The attack complexity is low, there are no
preexisting attack requirements; the privileges required are high, and
there is no user interaction required. The impact to system
confidentiality is low, the impact to system integrity is high and the
impact to system availability is low.
References
Link | Resource |
---|---|
https://www.absolute.com/platform/vulnerability-archive/cve-2025-27703 | Vendor Advisory |
Configurations
History
04 Jun 2025, 19:59
Type | Values Removed | Values Added |
---|---|---|
First Time |
Absolute secure Access
Absolute |
|
CPE | cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* | |
References | () https://www.absolute.com/platform/vulnerability-archive/cve-2025-27703 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.0 |
Summary |
|
29 May 2025, 00:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-281 |
28 May 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-28 21:15
Updated : 2025-06-04 19:59
NVD link : CVE-2025-27703
Mitre link : CVE-2025-27703
CVE.ORG link : CVE-2025-27703
JSON object : View
Products Affected
absolute
- secure_access
CWE
CWE-281
Improper Preservation of Permissions