Junglewise Threat Intelligence

CVE-2025-54603: Claroty Secure Access OIDC authentication bypass

CVE-2025-54603 · Severity: critical · CVSS 9 · Published 2025-10-14

Technologies: Claroty Secure Access.

Executive brief

Claroty Secure Access is a remote access and identity management platform used to secure critical infrastructure and industrial systems. An authentication flaw in OIDC configurations allows attackers to create unauthorized user accounts or impersonate existing users without proper authentication, potentially gaining administrator privileges and full control of the system.

Technical details

An incorrect implementation of the OpenID Connect (OIDC) authentication flow in Claroty Secure Access versions 3.3.0 through 4.0.2 allows unauthenticated network attackers to bypass authentication controls. The vulnerability affects on-premise deployments where OIDC is configured. An attacker can exploit this flaw to create new user accounts or impersonate existing OIDC users without valid credentials. In specific OIDC configurations, the attacker can further add a compromised or newly created user to the built-in Administrators group, gaining full administrative privileges over the Secure Access application. No user interaction is required for exploitation. Fixes are available in versions 3.7 and 4.0.2 via the customer portal.

Affected products

  • Claroty Secure Access 3.3.0 through 4.0.2

Timeline

  • 2025-10-08: disclosed
  • 2025-10-14: advisory

References