---
id: CVE-2025-54088
title: |-
  CVE-2025-54088 is an open-redirect vulnerability in Secure
  Access prior to version 14.10
summary: |-
  CVE-2025-54088 is an open-redirect vulnerability in Secure
  Access prior to version 14.10. Attackers with access to the console can
  redirect victims to an arbitrary URL. The attack complexity is low, attack
  requirements are present, no pr…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-601
vendor: absolute
product: secure_access
affected:
  - secure_access < 14.10
patched:
  - secure_access 14.10
published: '2025-10-02'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T23:10:00.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-54088'
references:
  - url: >-
      https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-54088
    label: SecurityResponse@netmotionsoftware.com
tags:
  - nvd
epss: 0.00184
epssPercentile: 0.07323
ingestedAt: '2026-10-08T23:16:47.360Z'
---

## Overview

CVE-2025-54088 is an open-redirect vulnerability in Secure
Access prior to version 14.10. Attackers with access to the console can
redirect victims to an arbitrary URL. The attack complexity is low, attack
requirements are present, no privileges are required, and users must actively
participate in the attack. Impact to confidentiality is low and there is no
impact to integrity or availability. There are high severity impacts to
confidentiality, integrity, availability in subsequent systems.

## Affected

- `secure_access < 14.10`

## Remediation

Upgrade past the affected range:

- `secure_access 14.10`
