CVE-2025-30236: Securenvoy Securaccess
High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.
Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 allows authentication through only a six-digit TOTP code (skipping a password check) if an HTTP POST request contains a SESSION parameter.
Affected products
- Securenvoy Securaccess: before 9.4.515 (fixed in 9.4.515)
Published 2025-03-19. Last modified 2026-06-17.