CVE-2025-27702

CVE-2025-27702 is a vulnerability in the management console of Absolute 
Secure Access prior to version 13.54. Attackers with administrative 
access to the console and who have been assigned a certain set of 
permissions can bypass those permissions to improperly modify settings. 
The attack complexity is low, there are no preexisting attack 
requirements; the privileges required are high, and there is no user 
interaction required. There is no impact to system confidentiality or 
availability, impact to system integrity is high.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
AbsoluteCNA
---
---
CISA-ADPADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%