Description
CVE-2026-55398
is a memory management vulnerability in Secure Access clients and servers prior
to 14.55. Attackers with intimate knowledge of and total control over the
tunnel protocol can create a non-persistent DoS against the server.
Published: 2026-07-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability stems from improper memory handling in Secure Access clients and servers. The flaw allows attackers with intimate knowledge of the tunnel protocol to trigger a non-persistent denial of service by sending a crafted tunnel message that causes improper buffer management and resource exhaustion, as indicated by the cited CWEs. The result is a temporary loss of service availability for legitimate users while the server recovers.

Affected Systems

Absolute Security's Secure Access is affected. Deployments running any version prior to 14.55 are vulnerable and must be upgraded to a supported release to eliminate the risk.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% shows a low likelihood of exploitation. This vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker must have direct control over the tunnel protocol—typically an insider or a compromised client—to exploit the vulnerability, limiting the attack path to environments where such control can be established. Nonetheless, once successful, it results in a denial of service to legitimate users until the server recovers.

Generated by OpenCVE AI on July 31, 2026 at 02:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Secure Access version 14.55 or later to remove the memory handling defect.
  • Enforce strict authentication and access controls on the tunnel protocol, limiting it to trusted clients only.
  • Monitor server resource usage for sudden spikes that could indicate an attempt to trigger the bug and respond promptly.

Generated by OpenCVE AI on July 31, 2026 at 02:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Absolute
Absolute secure Access
Vendors & Products Absolute
Absolute secure Access

Thu, 16 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server.
Title Memory management vulnerability in Secure Access clients
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Absolute Secure Access
cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-07-16T13:08:45.489Z

Reserved: 2026-06-16T21:26:37.698Z

Link: CVE-2026-55398

cve-icon Vulnrichment

Updated: 2026-07-16T13:08:41.543Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:00:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-400

    Uncontrolled Resource Consumption