CVE-2025-54087Low· 2.6▾ SunlitCVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can publish a crafted test HTTP request originating from the Secure Access server. The attack…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 14.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can publish a crafted test HTTP request originating from the Secure Access server. The attack complexity is high, there are no attack requirements, and user interaction is required. There is no direct impact to confidentiality, integrity, or availability. There is a low severity subsequent system impact to integrity.
secure_access < 14.10Upgrade past the affected range:
secure_access 14.10Connected by shared product, vendor, weakness, or advisory.
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents
CVE-2025-54088Medium· 6.1CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10
CVE-2025-54089Low· 3.4CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10
CVE-2025-54086Low· 3.3CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to version 14.10
CVE-2026-55402Medium· 5.9CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57
CVE-2026-55401Medium· 5.3CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57