CVE-2025-53118
—Unauthenticated Authentication Bypass in Unified PAM Exposes Stored Secrets
CVE-2025-53118 is an authentication bypass (CWE-306, missing authorization on a critical function) in Unified PAM, a privileged access management solution that stores passwords, secrets, and application session tokens. An unauthenticated remote attacker can reach and control administrator backup functions over the network without valid credentials and without any user interaction. By abusing these backup functions, the attacker can retrieve or manipulate backup data, yielding the passwords, secrets, and session tokens held in the vault, which can then be used to compromise downstream applications and accounts. Any organization running the affected Unified PAM deployment is exposed, with risk concentrated where the PAM interface is reachable from less-trusted networks. As of now there is no known public proof-of-concept and the flaw is not in CISA's KEV, but the high EPSS score (29.2% probability of exploitation within 30 days, 98th percentile) indicates elevated exploitation risk.
What to do: Upgrade Unified PAM to the vendor's patched release as soon as one is published (fixed version not specified in the available data), and meanwhile restrict network access to the PAM web/admin interface to trusted management networks. Monitor for unauthenticated requests to backup-related endpoints, and if compromise is suspected, rotate the passwords, secrets, and application session tokens stored in the vault.
| Unified PAM | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.