CVE-2025-54603

Critical severity, CVSS 9.0. EPSS: 0.7% chance of exploitation in the next 30 days.

An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users.

Published 2025-10-14. Last modified 2026-09-08.