{"id":"CVE-2025-54089","title":"CVE-2025-54089 is a cross-site scripting vulnerability in versions\nof secure access prior to 14.10","summary":"CVE-2025-54089 is a cross-site scripting vulnerability in versions\nof secure access prior to 14.10. Attackers with administrative access to the\nconsole can interfere with another administrator’s access to the console. The\nattack complexi…","severity":"low","cvss":3.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N","cwe":["CWE-79"],"vendor":"absolute","product":"secure_access","affected":["secure_access < 14.10"],"patched":["secure_access 14.10"],"published":"2025-10-02","updated":"2026-10-08","sourceUpdated":"2026-10-08T23:10:00.213","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-54089","references":[{"url":"https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-54089","label":"SecurityResponse@netmotionsoftware.com"}],"tags":["nvd"],"epss":0.00205,"epssPercentile":0.09649,"ingestedAt":"2026-10-08T23:16:47.360Z","slug":"CVE-2025-54089","body":"## Overview\n\nCVE-2025-54089 is a cross-site scripting vulnerability in versions\nof secure access prior to 14.10. Attackers with administrative access to the\nconsole can interfere with another administrator’s access to the console. The\nattack complexity is low; there are no attack requirements. Privileges required\nto execute the attack are high and the victim must actively participate in the\nattack sequence. There is no impact to confidentiality or availability, there\nis a low impact to integrity.\n\n## Affected\n\n- `secure_access < 14.10`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `secure_access 14.10`","depth":"sunlit","depthScore":19,"depthScoreParts":{"impact":18.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}