Description
CVE-2026-40952 is a privilege misconfiguration
in the Secure Access installer for the Windows client and server prior to
version 14.55. Attackers with local access to the client or server can use it
to elevate privileges to Administrator when Secure Access is installed in a
non-default location.
Published: 2026-07-15
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE-2026-40952 reveals a misconfiguration in the Secure Access installer for Windows clients and servers before version 14.55 that allows an attacker with local access to raise privileges to the Administrator level when the software is installed in a non‑default path. This flaw provides an unauthorized user with full administrative rights, enabling any subsequent actions normally restricted to elevated principals. The vulnerability corresponds to CWE‑276, indicating a flaw in privilege configuration.

Affected Systems

The affected systems are Absolute Security’s Secure Access client and server solutions on Windows environments, versions earlier than 14.55, when the installation directory diverges from the recommended default location. Users running these components in custom directories are at risk, while installations using the default path remain unaffected.

Risk and Exploitability

The CVSS score of 8.5 signals a high severity risk, yet the EPSS of less than 1% suggests a very low likelihood of widespread exploitation. The weakness is a local privilege escalation, not listed in the CISA KEV catalog, so public exploits are not currently documented. Attackers would need physical or remote local access to the machine and must install Secure Access in an alternate location to exploit the flaw.

Generated by OpenCVE AI on July 31, 2026 at 02:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Secure Access to version 14.55 or later to resolve the privilege misconfiguration.
  • If an upgrade cannot be performed immediately, reinstall Secure Access using the default installation directory, which prevents the elevation path exposed by this vulnerability.
  • Ensure local users do not run the installer or modify its installation path, and apply the principle of least privilege for all administrative accounts.

Generated by OpenCVE AI on July 31, 2026 at 02:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Absolute
Absolute secure Access
Vendors & Products Absolute
Absolute secure Access

Thu, 16 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a non-default location.
Title Privilge misconfiguration in Secure Access installers
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N'}


Subscriptions

Absolute Secure Access
cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-07-16T13:06:21.115Z

Reserved: 2026-04-16T00:19:03.573Z

Link: CVE-2026-40952

cve-icon Vulnrichment

Updated: 2026-07-16T13:06:16.488Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:00:06Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions