CVE-2025-27706

CVE-2025-27706 is a cross-site scripting vulnerability in the management
 console of Absolute Secure Access prior to version 13.54. Attackers 
with system administrator permissions can interfere with another system 
administrators use of the management console when the second 
administrator visits the page. Attack complexity is low, there are no 
preexisting attack requirements, privileges required are high and active
 user interaction is required. There is no impact on confidentiality, 
the impact on integrity is low and there is no impact on availability.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
AbsoluteCNA
---
---
CISA-ADPADP
---
---