Description
CVE-2026-40958
is a input validation error in Secure Access clients prior to 14.55. Attackers
with intimate knowledge of and total control over the tunnel protocol can
create a non-persistent DoS against their client.
Published: 2026-07-15
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an input validation error in Absolute Security Secure Access clients before version 14.55. An attacker who has intimate knowledge of, and full control over, the tunnel protocol can craft malformed input that causes the client to terminate or become unresponsive, resulting in a non-persistent denial of service. The weakness originates from improper input handling and is classified as CWE‑20.

Affected Systems

Absolute Security’s Secure Access product is affected; any installation of the client that is earlier than version 14.55 is vulnerable. Later releases, starting with 14.55, are not impacted.

Risk and Exploitability

The CVSS score of 2.3 indicates a low severity; the EPSS score is reported as less than 1 %, implying a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited known exploitation. Based on the description, the likely attack vector requires an adversary with extensive knowledge of the tunnel protocol and direct control over the communication channel. Therefore, the practical attack vector is limited to an entity with privileged or compromised tunnel access rather than a broad remote attacker.

Generated by OpenCVE AI on July 31, 2026 at 02:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch that upgrades Secure Access to version 14.55 or newer.
  • Ensure that client input validation for tunnel messages follows best practices to prevent malformed packets from affecting application state.
  • Monitor client logs for repeated connection resets or abnormal traffic that may indicate attempted DoS attacks.
  • If upgrading is not immediately possible, restrict tunnel access to trusted users and consider temporarily disabling features that process external tunnel data until a fix can be applied.

Generated by OpenCVE AI on July 31, 2026 at 02:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Absolute
Absolute secure Access
Vendors & Products Absolute
Absolute secure Access

Thu, 16 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.
Title Input validation error in Secure Access clients prior to 14.55
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Absolute Secure Access
cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-07-16T13:11:50.471Z

Reserved: 2026-04-16T00:19:03.574Z

Link: CVE-2026-40958

cve-icon Vulnrichment

Updated: 2026-07-16T13:11:47.193Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:00:06Z

Weaknesses
  • CWE-20

    Improper Input Validation