CVE-2025-60534
Critical · CVSS 9.8Blue Access Cobalt — Authentication Bypass via Selective Proxy Request Manipulation
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-287
Description
Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order to operate functionality on the web application without the need to authenticate with legitimate credentials.
Search profile — drives PoC discovery
Symbols Blue Access Cobaltv02.000.195proxy requestauthentication bypassweb application unauthenticated access
Keywords CVE-2025-60534Blue Access Cobalt authentication bypassBlue Access Cobalt v02.000.195Cobalt auth bypass proxyCWE-287 Blue Access CobaltPilotPatrickk CVE-2025-60534
Versions: v02.000.195
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z