Impact
CVE-2026-40952 reveals a misconfiguration in the Secure Access installer for Windows clients and servers before version 14.55 that allows an attacker with local access to raise privileges to the Administrator level when the software is installed in a non‑default path. This flaw provides an unauthorized user with full administrative rights, enabling any subsequent actions normally restricted to elevated principals. The vulnerability corresponds to CWE‑276, indicating a flaw in privilege configuration.
Affected Systems
The affected systems are Absolute Security’s Secure Access client and server solutions on Windows environments, versions earlier than 14.55, when the installation directory diverges from the recommended default location. Users running these components in custom directories are at risk, while installations using the default path remain unaffected.
Risk and Exploitability
The CVSS score of 8.5 signals a high severity risk, yet the EPSS of less than 1% suggests a very low likelihood of widespread exploitation. The weakness is a local privilege escalation, not listed in the CISA KEV catalog, so public exploits are not currently documented. Attackers would need physical or remote local access to the machine and must install Secure Access in an alternate location to exploit the flaw.
OpenCVE Enrichment