Description
CVE-2026-55399 is a resource exhaustion
vulnerability in the Secure Access publisher prior to 14.55. Attackers with
valid credentials to the Secure Access tunnel can create a non-persistent DoS
against the publisher.
Published: 2026-07-15
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE-2026-55399 is a resource exhaustion vulnerability that permits an authenticated attacker with access to the Secure Access tunnel to initiate a brief service interruption against the publisher. The flaw is triggered through valid credentials and leads to denial of service by exhausting limited resources after each authentication attempt. It is classified as CWE-400 and does not provide privilege escalation or code execution.

Affected Systems

The vulnerability affects the Secure Access publisher component of Absolute Security’s product suite. Versions prior to 14.55 are affected; all newer releases have an additional fix. Attackers must possess valid credentials to the Secure Access tunnel to exploit the flaw.

Risk and Exploitability

The CVSS score of 5.1 places this issue in the medium severity range. The EPSS score is less than 1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The required attack vector is authenticated access to the Secure Access tunnel, which limits exposure to customers with active user accounts. While an attacker can repeatedly trigger the denial of service, the flaw does not allow elevation of privileges or data exfiltration.

Generated by OpenCVE AI on July 31, 2026 at 02:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade or patch the Secure Access publisher to version 14.55 or later, which removes the resource exhaustion flaw
  • Limit or audit credentials for the Secure Access tunnel; assign only necessary privileges and disable unused accounts
  • Implement network segmentation or rate-limiting on the Secure Access tunnel to mitigate repeated DoS attempts

Generated by OpenCVE AI on July 31, 2026 at 02:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Absolute
Absolute secure Access
Vendors & Products Absolute
Absolute secure Access

Thu, 16 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create a non-persistent DoS against the publisher.
Title Resource exhaustion vulnerability in the Secure Access publisher
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Absolute Secure Access
cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-07-16T13:07:32.872Z

Reserved: 2026-06-16T21:26:37.698Z

Link: CVE-2026-55399

cve-icon Vulnrichment

Updated: 2026-07-16T13:07:28.529Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:00:06Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption