---
id: CVE-2025-54089
title: |-
  CVE-2025-54089 is a cross-site scripting vulnerability in versions
  of secure access prior to 14.10
summary: |-
  CVE-2025-54089 is a cross-site scripting vulnerability in versions
  of secure access prior to 14.10. Attackers with administrative access to the
  console can interfere with another administrator’s access to the console. The
  attack complexi…
severity: low
cvss: 3.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N'
cwe:
  - CWE-79
vendor: absolute
product: secure_access
affected:
  - secure_access < 14.10
patched:
  - secure_access 14.10
published: '2025-10-02'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T23:10:00.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-54089'
references:
  - url: >-
      https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-54089
    label: SecurityResponse@netmotionsoftware.com
tags:
  - nvd
epss: 0.00205
epssPercentile: 0.09649
ingestedAt: '2026-10-08T23:16:47.360Z'
---

## Overview

CVE-2025-54089 is a cross-site scripting vulnerability in versions
of secure access prior to 14.10. Attackers with administrative access to the
console can interfere with another administrator’s access to the console. The
attack complexity is low; there are no attack requirements. Privileges required
to execute the attack are high and the victim must actively participate in the
attack sequence. There is no impact to confidentiality or availability, there
is a low impact to integrity.

## Affected

- `secure_access < 14.10`

## Remediation

Upgrade past the affected range:

- `secure_access 14.10`
