CVE-2026-0518

MEDIUM

Absolute Secure Access < 14.20 - Authenticated Cross-Site Scripting

Title source: llm
STIX 2.1

Description

CVE-2026-0518 is a cross-site scripting vulnerability in versions of Secure Access prior to 14.20. An attacker with administrative privileges can interfere with another administrator’s use of the console.

Scores

CVSS v3 4.8
EPSS 0.0014
EPSS Percentile 4.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
absolute/secure_access < 14.20
Published Jan 17, 2026
Tracked Since Feb 18, 2026