Description
CVE-2026-40953 is a heap overflow in the
certificate parsing function of Secure Access clients prior to 14.55. Attackers
with local access and administrator permissions can create a denial of service
attack against the client over which they have control.
Published: 2026-07-15
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a heap overflow in the certificate parsing function of Absolute Security Secure Access clients prior to version 14.55. It allows a local attacker with administrator permissions to manipulate the parsing process, triggering an out-of-bounds write that leads to a denial of service of the client application. The weakness is a classic out-of-bounds write (CWE‑787), causing loss of availability for users relying on the client.

Affected Systems

Affected products are Absolute Security Secure Access clients with versions earlier than 14.55. Administrators with local system access to these clients are required to exploit the flaw.

Risk and Exploitability

The CVSS base score of 6.7 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, and exploitation requires local administrative access, which limits its attack surface. Nonetheless, once an authorized local user activates the payload, the client will crash and become unavailable until the process is restarted or the software is upgraded.

Generated by OpenCVE AI on July 31, 2026 at 02:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Absolute Security Secure Access to version 14.55 or later.
  • Restrict local administrative privileges on machines running the Secure Access client to only those who truly require them.
  • Monitor the client for unexpected crashes and apply interim patches or configuration changes recommended by the vendor.

Generated by OpenCVE AI on July 31, 2026 at 02:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Absolute
Absolute secure Access
Vendors & Products Absolute
Absolute secure Access

Thu, 16 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can create a denial of service attack against the client over which they have control.
Title Heap overflow in Secure Access clients
References
Metrics cvssV4_0

{'score': 6.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Absolute Secure Access
cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-07-16T13:15:46.358Z

Reserved: 2026-04-16T00:19:03.573Z

Link: CVE-2026-40953

cve-icon Vulnrichment

Updated: 2026-07-16T13:15:41.987Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:00:06Z

Weaknesses