---
id: CVE-2025-54087
title: |-
  CVE-2025-54087 is a server-side request forgery
  vulnerability in Secure Access prior to version 14.10
summary: |-
  CVE-2025-54087 is a server-side request forgery
  vulnerability in Secure Access prior to version 14.10. Attackers with
  administrative privileges can publish a crafted test HTTP request originating
  from the Secure Access server. The attack…
severity: low
cvss: 2.6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:N'
cwe:
  - CWE-918
vendor: absolute
product: secure_access
affected:
  - secure_access < 14.10
patched:
  - secure_access 14.10
published: '2025-10-02'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T23:10:00.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-54087'
references:
  - url: >-
      https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-54087
    label: SecurityResponse@netmotionsoftware.com
tags:
  - nvd
epss: 0.00184
epssPercentile: 0.07313
ingestedAt: '2026-10-08T23:16:47.358Z'
---

## Overview

CVE-2025-54087 is a server-side request forgery
vulnerability in Secure Access prior to version 14.10. Attackers with
administrative privileges can publish a crafted test HTTP request originating
from the Secure Access server. The attack complexity is high, there are no
attack requirements, and user interaction is required. There is no direct
impact to confidentiality, integrity, or availability. There is a low severity
subsequent system impact to integrity.

## Affected

- `secure_access < 14.10`

## Remediation

Upgrade past the affected range:

- `secure_access 14.10`
