A AegiFlow
CRITICALCVSS 9.0

CVE-2025-54603

CVE-2025-54603 updated by NVD

Modified
2026-09-10
Sources
nvd

Summary

An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users.

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.