Impact
CVE-2026-33445 is a memory‑management defect that could allow an attacker to trigger a persistent denial of service by exhausting server memory. The flaw is triggered when specially crafted tunnel traffic is processed, causing allocation errors and eventual crash or hang. The weakness is classified as CWE‑400. The description indicates that a malicious actor who can control the tunnel traffic and has detailed protocol knowledge could create a persistent DoS; the characterization of the attacker as remote is inferred rather than directly stated.
Affected Systems
Absolute Security’s Secure Access server versions earlier than 14.55 are affected, regardless of sub‑version details. No other vendor or product has been identified as vulnerable.
Risk and Exploitability
The CVSS score of 8.7 signals high severity. The EPSS score is below 1 %, indicating a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no documented widespread use. The analysis infers that effective exploitation requires deep protocol knowledge and control over the tunnel, limiting the attack surface to insiders or privileged network operators. Nonetheless, a successful attack would lead to service disruption and loss of availability.
OpenCVE Enrichment