CVE-2025-27703 Details
Description
CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to a specific subset of privileged features in the console can elevate their permissions to access additional features in the console. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. The impact to system confidentiality is low, the impact to system integrity is high and the impact to system availability is low.
A privilege escalation vulnerability has been identified in the management console of Absolute Secure Access, affecting versions prior to 13.54. This vulnerability allows attackers with administrative access to certain privileged features in the console to elevate their permissions and access additional features. The vulnerability has a low attack complexity, requires high privileges, and does not involve user interaction. While the impact on system confidentiality is low and availability is also low, the vulnerability significantly affects system integrity.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.absolute.com/platform/vulnerability-archive/cve-2025-27703 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-281 | Improper Preservation of Permissions | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| absolute secure access | < 13.54 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2025 | Initial Analysis | [email protected] |
| May 29, 2025 | CVE Modified | CISA-ADP |
| May 28, 2025 | New CVE Received | [email protected] |