CVE-2025-54088 is an open-redirect vulnerability in Secure
Access prior to version 14.10. Attackers with access to the console can
redirect victims to an arbitrary URL. The attack complexity is low, attack
requirements are present, no privileges are required, and users must actively
participate in the attack. Impact to confidentiality is low and there is no
impact to integrity or availability. There are high severity impacts to
confidentiality, integrity, availability in subsequent systems.
References
| Link | Resource |
|---|---|
| https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-54088 | Vendor Advisory |
Configurations
History
16 Oct 2025, 18:22
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* | |
| First Time |
Absolute secure Access
Absolute |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| References | () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-54088 - Vendor Advisory |
07 Oct 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-601 |
02 Oct 2025, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-02 21:16
Updated : 2025-10-16 18:22
NVD link : CVE-2025-54088
Mitre link : CVE-2025-54088
CVE.ORG link : CVE-2025-54088
JSON object : View
Products Affected
absolute
- secure_access
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
