Impact
CVE-2026-40954 is an integer underflow flaw in the traffic parsing routine of the Secure Access client. The underflow is triggered when an attacker, who has intimate knowledge of and full control over the tunnel protocol, sends specially crafted packets. The effect is a non-persistent DoS that causes the client application to crash or become unresponsive for the session, but does not allow remote code execution or persistent disruption.
Affected Systems
The vulnerability affects Secure Access clients from Absolute Security with versions earlier than 14.55. All software prior to the 14.55 release is considered vulnerable.
Risk and Exploitability
The CVSS score of 2.1 indicates low severity, and the EPSS score of less than 1% confirms a very low probability of exploitation. Based on the description, it is inferred that exploitation requires the attacker to control the tunnel protocol, implying a high‑privilege or insider attacker, and the weakness is an integer underflow (CWE-191). The vulnerability is not listed in CISA's KEV catalog. Exploitation would lead to a non‑persistent DoS affecting only the local client session.
OpenCVE Enrichment