Description
CVE-2026-40956
is a memory disclosure vulnerability in Secure Access client versions prior to 14.55.
Attackers with intimate knowledge of and total control over the tunnel protocol
can cause a small amount of random memory to leak.
Published: 2026-07-15
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A memory disclosure exists in the Secure Access client before version 14.55 that can expose a small amount of random memory. The vulnerability is classified as CWE‑200, a weakness that can leak sensitive data and potentially enable attackers to obtain confidential information from the client process.

Affected Systems

Absolute Security Secure Access client users with installed releases earlier than version 14.55 are vulnerable. Any instance of the client exposed through a tunnel is susceptible if the attacker controls the tunnel protocol.

Risk and Exploitability

The CVSS score of 2.1 indicates limited impact, and the EPSS score of less than 1 % reflects a very low likelihood of exploitation under current conditions. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that exploitation requires intimate knowledge of and full control over the tunnel protocol, implying that only attackers with privileged network access or insider capabilities could trigger the memory leak. Therefore, the overall risk remains low but should be mitigated by updating the software and limiting tunnel control to trusted hosts.

Generated by OpenCVE AI on July 31, 2026 at 02:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Secure Access client to version 14.55 or later to remove the memory disclosure issue.
  • Restrict control of the tunnel protocol to trusted internal hosts to prevent attackers from exploiting the memory leak.
  • Enable logging and audit of tunnel control interactions to detect and respond to unauthorized manipulation attempts.

Generated by OpenCVE AI on July 31, 2026 at 02:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Absolute
Absolute secure Access
Vendors & Products Absolute
Absolute secure Access

Thu, 16 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can cause a small amount of random memory to leak.
Title Memory disclosure in Secure Access Clients
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Absolute Secure Access
cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-07-16T13:12:35.493Z

Reserved: 2026-04-16T00:19:03.574Z

Link: CVE-2026-40956

cve-icon Vulnrichment

Updated: 2026-07-16T13:12:31.765Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:00:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor