CVE-2025-27703 - CVE House
Back to Database
Status published High CVE-2025-27703

Privilege escalation in the management console of Absolute Secure Access prior to version 13.54

Vulnerability Description

CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to a specific subset of privileged features in the console can elevate their permissions to access additional features in the console. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. The impact to system confidentiality is low, the impact to system integrity is high and the impact to system availability is low.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-27703

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Absolute Security

View all reports →

Affected Software

Secure Access
Vulnerable Versions:
0

Timeline

Official Publish: May 28th, 2025
Last Modified: May 28th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.