CVE-2025-49082

CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly read other settings. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. The impact to system confidentiality is low, there is no impact to system availability or integrity.
Configurations

Configuration 1 (hide)

cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-07-31 00:15

Updated : 2025-08-05 20:16


NVD link : CVE-2025-49082

Mitre link : CVE-2025-49082

CVE.ORG link : CVE-2025-49082


JSON object : View

Products Affected

absolute

  • secure_access
CWE
CWE-276

Incorrect Default Permissions