CVE-2025-30236: Securenvoy Securaccess

High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.

Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 allows authentication through only a six-digit TOTP code (skipping a password check) if an HTTP POST request contains a SESSION parameter.

Affected products

  • Securenvoy Securaccess: before 9.4.515 (fixed in 9.4.515)

Published 2025-03-19. Last modified 2026-06-17.