CVE-2025-32408: Soffid Iam

Low severity, CVSS 2.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In Soffid Console 3.6.31 before 3.6.32, authorization to use the pam service is mishandled.

Affected products

  • Soffid Iam: from 3.6.31, before 3.6.32 (fixed in 3.6.32)

Published 2025-04-21. Last modified 2026-06-17.