CVE-2025-54089 is a cross-site scripting vulnerability in versions
of secure access prior to 14.10. Attackers with administrative access to the
console can interfere with another administrator’s access to the console. The
attack complexity is low; there are no attack requirements. Privileges required
to execute the attack are high and the victim must actively participate in the
attack sequence. There is no impact to confidentiality or availability, there
is a low impact to integrity.
References
Link | Resource |
---|---|
https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-54089 | Vendor Advisory |
Configurations
History
16 Oct 2025, 18:21
Type | Values Removed | Values Added |
---|---|---|
First Time |
Absolute
Absolute secure Access |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.4 |
References | () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-54089 - Vendor Advisory | |
CPE | cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* |
03 Oct 2025, 16:16
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 |
02 Oct 2025, 21:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-10-02 21:16
Updated : 2025-10-16 18:21
NVD link : CVE-2025-54089
Mitre link : CVE-2025-54089
CVE.ORG link : CVE-2025-54089
JSON object : View
Products Affected
absolute
- secure_access
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')