Description
o  
CVE-2026-40957 is a frameable content
vulnerability in the Secure Access server login page prior to 14.55. Attackers
with control of a malicious web site could use it to potentially steal
credentials from an unwary administrator.
Published: 2026-07-15
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A frameable content flaw exists in the login page of Absolute Security Secure Access before version 14.55. The web application allows the login page to be embedded in an attacker‑controlled frame without proper frame‑busting headers or policy. When an administrator interacts with a malicious or compromised web site that frames the vulnerable login page, the credentials entered are captured by the attacker. This weakness, classified as CWE‑1021, permits the theft of authenticating credentials, potentially enabling privileged access to the protected environment.

Affected Systems

Absolute Security Secure Access servers running any version earlier than 14.55 are vulnerable. Administrators who log in to the vulnerable login page are at risk when they visit a malicious or compromised web site that frames the login page.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity, and the EPSS score of less than 1% suggests a low current exploit likelihood. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to control a malicious website and for the target administrator to load the framed login page in a browser that does not enforce anti‑framing protections. Successful exploitation results in credential theft; it does not provide direct code execution or arbitrary system access, but the stolen credentials can be used for further compromise if additional safeguards are absent.

Generated by OpenCVE AI on July 31, 2026 at 02:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Absolute Security Secure Access to version 14.55 or later to remove the frameable login page.
  • Configure the web server or application to include the header X‑Frame‑Options: DENY or a CSP frame‑ancestors directive that blocks framing of the login page.
  • Implement multi‑factor authentication for all administrative logins to reduce the impact of stolen credentials.

Generated by OpenCVE AI on July 31, 2026 at 02:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Absolute
Absolute secure Access
Vendors & Products Absolute
Absolute secure Access

Thu, 16 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1021
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description o   CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator.
Title Frameable content vulnerability in the Secure Access server login page
References
Metrics cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N'}


Subscriptions

Absolute Secure Access
cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-07-16T13:16:38.543Z

Reserved: 2026-04-16T00:19:03.574Z

Link: CVE-2026-40957

cve-icon Vulnrichment

Updated: 2026-07-16T13:16:35.010Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:00:06Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames