Description
CVE-2026-40954
is an integer underflow vulnerability in the traffic parsing function of Secure
Access clients prior to 14.55. Attackers with intimate knowledge of and total
control over the tunnel protocol can create a non-persistent DoS against their
client
Published: 2026-07-15
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE-2026-40954 is an integer underflow flaw in the traffic parsing routine of the Secure Access client. The underflow is triggered when an attacker, who has intimate knowledge of and full control over the tunnel protocol, sends specially crafted packets. The effect is a non-persistent DoS that causes the client application to crash or become unresponsive for the session, but does not allow remote code execution or persistent disruption.

Affected Systems

The vulnerability affects Secure Access clients from Absolute Security with versions earlier than 14.55. All software prior to the 14.55 release is considered vulnerable.

Risk and Exploitability

The CVSS score of 2.1 indicates low severity, and the EPSS score of less than 1% confirms a very low probability of exploitation. Based on the description, it is inferred that exploitation requires the attacker to control the tunnel protocol, implying a high‑privilege or insider attacker, and the weakness is an integer underflow (CWE-191). The vulnerability is not listed in CISA's KEV catalog. Exploitation would lead to a non‑persistent DoS affecting only the local client session.

Generated by OpenCVE AI on July 31, 2026 at 02:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to version 14.55 or later of the Secure Access client, which includes a fix for the integer underflow (CWE-191).
  • If an upgrade cannot be performed immediately, isolate the client from untrusted traffic or configure the firewall to block raw packets that could trigger the underflow, mitigating the integer underflow risk (CWE-191).
  • Plan and execute a patch deployment cycle targeting all installations using Secure Access prior to 14.55 to upgrade them promptly.

Generated by OpenCVE AI on July 31, 2026 at 02:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Absolute
Absolute secure Access
Vendors & Products Absolute
Absolute secure Access

Thu, 16 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-191
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client
Title Integer underflow in Secure Access clients prior to 14.55
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Absolute Secure Access
cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-07-16T13:15:09.379Z

Reserved: 2026-04-16T00:19:03.573Z

Link: CVE-2026-40954

cve-icon Vulnrichment

Updated: 2026-07-16T13:15:06.223Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:00:06Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)