Improper Authentication in KACE Systems Management Appliance (SMA) - CVE-2025-32975
Published: April 24, 2026
KACE Systems Management Appliance (SMA)
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication and impersonate legitimate users.
The vulnerability exists due to improper authentication in the SSO authentication handling mechanism when processing authentication requests. A remote attacker can impersonate any valid username to bypass authentication and impersonate legitimate users.
The issue can lead to complete administrative takeover of the appliance.