Unknown · Abnormal Security · CVE-2025-54596
**Name of the Vulnerable Software and Affected Versions**
Abnormal Security versions prior to 2025-02-19
**Description**
The software contains an issue that allows downgrading the privileges of other user accounts. The issue is related to the `/v1.0/rbac/users v2/{USER ID}/` API endpoint, where `USER ID` is a vulnerable parameter.
**Recommendations**
Update to a version released on or after 2025-02-19.