CVE-2025-49083
CVE-2025-49083 is a high-severity vulnerability in Absolute Secure Access with a CVSS 3.x base score of 7.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-502.
Key facts
- Severity: High (CVSS 3.x base score 7.2)
- CVSS v4: 7.0
- EPSS exploit prediction: 0% (30th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-23218
- Weakness: CWE-502
- Affected product: Absolute Secure Access
- Published:
- Last modified:
Description
CVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. Attackers with administrative access to the console can cause unsafe content to be deserialized and executed in the security context of the console. The attack complexity is low and there are no attack requirements. Privileges required are high and there is no user interaction required. The impact to confidentiality is low, impact to integrity is high and there is no impact to availability. The impact to the confidentiality and integrity of subsequent systems is low and there is no subsequent system impact to availability.
Frequently asked questions
- What is CVE-2025-49083?
- CVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. Attackers with administrative access to the console can cause unsafe content to be deserialized and executed in the security context of the console. The attack complexity is low and there are no attack requirements. Privileges required are high and there is no user interaction required. The impact to confidentiality is low, impact to integrity is high and there is no impact to availability. The impact to the confidentiality and integrity of subsequent systems is low and there is no subsequent system impact to availability.
- How severe is CVE-2025-49083?
- CVE-2025-49083 has a CVSS 3.x base score of 7.2, rated high severity. It is exploitable over network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2025-49083 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (30th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-49083?
- CVE-2025-49083 affects Absolute Secure Access. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-49083?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2025-49083 have an EU (EUVD) identifier?
- Yes. CVE-2025-49083 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-23218.
- When was CVE-2025-49083 published?
- CVE-2025-49083 was published on 2025-07-31 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*
More vulnerabilities in Absolute Secure Access
- CVE-2026-33447 — Critical (CVSS 9.8): CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50.…
- CVE-2026-33446 — Critical (CVSS 9.8): CVE-2026-33446 is a buffer overflow in the authentication sub-system of the Secure Access client prior to 14.50.…
- CVE-2025-49084 — Critical (CVSS 9.1): CVE-2025-49084 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers…
- CVE-2026-40952 — High (CVSS 7.8): CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior…
- CVE-2026-33451 — High (CVSS 7.8): CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers…
- CVE-2026-40957 — High (CVSS 7.5): o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55.…
All CVEs affecting Absolute Secure Access →
Other CWE-502 (Deserialization of Untrusted Data) vulnerabilities
- CVE-2026-69836 — Critical (CVSS 10.0): Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
- CVE-2026-17061 — Critical (CVSS 10.0): A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release…
- CVE-2026-11756 — Critical (CVSS 10.0): A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release…
- CVE-2026-41104 — Critical (CVSS 10.0): Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose…
- CVE-2026-43633 — Critical (CVSS 10.0): HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a…
- CVE-2026-33819 — Critical (CVSS 10.0): Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
Browse all CWE-502 (Deserialization of Untrusted Data) vulnerabilities →