CVE-2026-55402

8.7

Absolute Security · Secure Access

Absolute Security Secure Access servers prior to version 14.57 contain an out-of-bounds read vulnerability that could lead to system instability or information disclosure.

Executive summary

An out-of-bounds read vulnerability in Absolute Security Secure Access servers creates a critical risk of system instability or unauthorized memory access.

Vulnerability

The software suffers from an out-of-bounds read vulnerability in its server component. An unauthenticated remote attacker can trigger this flaw by sending specially crafted network requests to the target, potentially resulting in service crashes or the disclosure of sensitive memory contents.

Business impact

The vulnerability carries a CVSS score of 8.7, indicating a high risk to system availability and confidentiality. Successful exploitation could allow an attacker to disrupt critical network access services, leading to downtime for end users. Furthermore, the potential for memory disclosure poses a risk to the integrity of sensitive data processed by the server.

Remediation

Immediate Action: Upgrade all instances of Secure Access server software to version 14.57 or higher immediately.

Proactive Monitoring: Review system logs for unexpected service restarts or segmentation faults, which may indicate an attempt to trigger the out-of-bounds read.

Compensating Controls: Use network-level access controls to restrict traffic to the Secure Access server, ensuring only authorized sources can interact with the management and data interfaces.

Exploitation status

Public Exploit Available: No (exploit_available unknown).

Analyst recommendation

Due to the severity of this vulnerability and the potential for service disruption, administrators must treat this update with high priority. Ensure all server instances are patched to version 14.57 to remediate the underlying memory safety issue.

More Absolute Security CVEs