Junglewise Threat Intelligence

CVE-2025-32975: Quest KACE Systems Management Appliance authentication bypass in SSO

CVE-2025-32975 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2026-04-20

Technologies: Quest KACE Systems Management Appliance (SMA), Quest KACE Systems Management Appliance. Vendors: Quest.

Executive brief

Quest KACE Systems Management Appliance (SMA) is a tool used by organizations to manage and secure computers, servers, and connected devices. A critical security flaw allows unauthorized individuals to bypass login requirements and impersonate legitimate users, including administrators. This could lead to a complete takeover of the management system, allowing attackers to access sensitive data or disrupt IT operations across the entire network.

Technical details

An improper authentication vulnerability (CWE-287) exists in the Single Sign-On (SSO) authentication handling mechanism of the Quest KACE Systems Management Appliance (SMA). The flaw allows a remote, unauthenticated attacker to bypass security checks and impersonate any legitimate user, including those with administrative privileges. This vulnerability is exploitable over the network without user interaction. Successful exploitation results in a complete administrative takeover of the appliance. Patches have been released for versions 13.0, 13.1, 13.2, 14.0, and 14.1.

Affected products

  • Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4)

Timeline

  • 2025-06-24: disclosed: Initial CVE publication
  • 2026-04-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats