CISA's Metasys advisory (CVE-2026-34491) describes low-privilege XSS that executes in admin sessions. Every action it takes will be logged as the admin.