CVE-2025-59453
Status: DeferredLow (3.2)—
Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a crafted URL while on the Emergency Access web page, an unauthorized person can gain access to the Passwordstate Administration section.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
- Base score: 3.2
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.15%
- Percentile among all scored CVEs: 4
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-669
References
Raw JSON (NVD)
Show
{
"id": "CVE-2025-59453",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-59453",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-09-16T19:14:34.544071Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 3.2,
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 1.4
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "clickstudios",
"product": "Passwordstate",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "9.9 Build 9972",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-09-16T06:16:06.163",
"references": [
{
"url": "https://www.clickstudios.com.au/passwordstate-changelog.aspx",
"source": "cve@mitre.org"
},
{
"url": "https://www.clickstudios.com.au/security/advisories/",
"source": "cve@mitre.org"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"description": [
{
"lang": "en",
"value": "CWE-669"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a crafted URL while on the Emergency Access web page, an unauthorized person can gain access to the Passwordstate Administration section."
},
{
"lang": "es",
"value": "Click Studios Passwordstate anterior a la versión 9.9 Build 9972 tiene una posible omisión de autenticación para el acceso de emergencia de Passwordstate. Al usar una URL manipulada mientras se encuentra en la página web de Acceso de Emergencia, una persona no autorizada puede obtener acceso a la sección de Administración de Passwordstate."
}
],
"lastModified": "2026-09-30T23:10:00.237",
"sourceIdentifier": "cve@mitre.org"
}