CVE-2025-54086Low· 3.3▾ SunlitCVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to version 14.10. Attackers with access to the local file system can read the Java keystore file. The attack complexity is l…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 18.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to version 14.10. Attackers with access to the local file system can read the Java keystore file. The attack complexity is low, there are no attack requirements, the privileges required are low and no user interaction is required. Impact to confidentiality is low, there is no impact to integrity or availability.
secure_access < 14.10Upgrade past the affected range:
secure_access 14.10Connected by shared product, vendor, weakness, or advisory.
CVE-2025-54088Medium· 6.1CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10
CVE-2025-54089Low· 3.4CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10
CVE-2025-54087Low· 2.6CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10
CVE-2026-55402Medium· 5.9CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57
CVE-2026-55401Medium· 5.3CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57
CVE-2026-55400Medium· 6.5CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57