CVE-2025-54089Low· 3.4▾ SunlitCVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with administrative access to the console can interfere with another administrator’s access to the console. The attack complexi…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 18.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with administrative access to the console can interfere with another administrator’s access to the console. The attack complexity is low; there are no attack requirements. Privileges required to execute the attack are high and the victim must actively participate in the attack sequence. There is no impact to confidentiality or availability, there is a low impact to integrity.
secure_access < 14.10Upgrade past the affected range:
secure_access 14.10Connected by shared product, vendor, weakness, or advisory.
CVE-2025-54088Medium· 6.1CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10
CVE-2025-54086Low· 3.3CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to version 14.10
CVE-2025-54087Low· 2.6CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10
CVE-2026-55402Medium· 5.9CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57
CVE-2026-55401Medium· 5.3CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57
CVE-2026-55400Medium· 6.5CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57