Description
CVE-2026-40955 is an integer underflow
vulnerability in the traffic parsing function of Secure Access clients prior to
14.55. Attackers with intimate knowledge of and total control over the tunnel
protocol can create a non-persistent DoS against their client.
Published: 2026-07-15
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer underflow occurs in the traffic parsing routine of Absolute Security’s Secure Access client before version 14.55. When a malformed tunnel packet is processed, the underflow corrupts an internal counter, causing the client to crash or restart. The flaw does not reveal data or grant elevated privileges; it only disrupts the availability of the affected client.

Affected Systems

All installations of the Secure Access client released prior to 14.55 are vulnerable. This includes every pre‑14.55 build of the client, as no sub‑identifiers indicate a narrower scope.

Risk and Exploitability

The CVSS score of 2.1 classifies the vulnerability as low severity, and the EPSS score of less than 1% suggests exploitation is rare but still possible. The flaw is not listed in CISA’s KEV catalog. Attackers must have intimate knowledge of the tunnel protocol and total control over the traffic they send, implying a privileged or compromised environment where the attacker can dictate tunnel traffic. The resulting damage is a non‑persistent denial of service that does not compromise data or network configuration.

Generated by OpenCVE AI on July 31, 2026 at 02:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Secure Access clients to version 14.55 or newer to eliminate the integer underflow flaw.
  • Restrict the tunnel interface to trusted IP ranges or subnets using firewalls or access control lists so that only authorized traffic can reach the client.
  • Enable detailed logging of tunnel packet processing errors and monitor for repeated client restarts, setting up alerts for abnormal patterns.

Generated by OpenCVE AI on July 31, 2026 at 02:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Absolute
Absolute secure Access
Vendors & Products Absolute
Absolute secure Access

Thu, 16 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-191
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.
Title Integer underflow vulnerability in Secure Access clients
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Absolute Secure Access
cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-07-16T13:13:12.587Z

Reserved: 2026-04-16T00:19:03.573Z

Link: CVE-2026-40955

cve-icon Vulnrichment

Updated: 2026-07-16T13:13:09.789Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:00:06Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)