CVE-2026-0518: XSS in Secure Access Consoles prior to 14.20
Published Jan 17, 2026
·Updated
CVE-2026-0518 is a cross-site scripting vulnerability in versions of Secure Access prior to 14.20. An attacker with administrative privileges can interfere with another administrator’s use of the console.
Affected Software
2 affected components
Secure Access Secure Access<14.20
Absolute Secure Access<14.20
Event History
Jan 17, 2026
CVE Published
via MITRE·01:09 AM
Data Sourced
via MITRE·01:09 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-0518?
CVE-2026-0518 is classified as a medium severity cross-site scripting vulnerability in Secure Access.
2
How do I fix CVE-2026-0518?
To fix CVE-2026-0518, upgrade to Secure Access version 14.20 or later.
3
Who is affected by CVE-2026-0518?
CVE-2026-0518 affects users of Secure Access versions prior to 14.20, specifically those with administrative privileges.
4
What type of vulnerability is CVE-2026-0518?
CVE-2026-0518 is a cross-site scripting (XSS) vulnerability.
5
Can an attacker exploit CVE-2026-0518 without administrative privileges?
No, an attacker must have administrative privileges to exploit CVE-2026-0518.