Impact
CVE-2026-55399 is a resource exhaustion vulnerability that permits an authenticated attacker with access to the Secure Access tunnel to initiate a brief service interruption against the publisher. The flaw is triggered through valid credentials and leads to denial of service by exhausting limited resources after each authentication attempt. It is classified as CWE-400 and does not provide privilege escalation or code execution.
Affected Systems
The vulnerability affects the Secure Access publisher component of Absolute Security’s product suite. Versions prior to 14.55 are affected; all newer releases have an additional fix. Attackers must possess valid credentials to the Secure Access tunnel to exploit the flaw.
Risk and Exploitability
The CVSS score of 5.1 places this issue in the medium severity range. The EPSS score is less than 1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The required attack vector is authenticated access to the Secure Access tunnel, which limits exposure to customers with active user accounts. While an attacker can repeatedly trigger the denial of service, the flaw does not allow elevation of privileges or data exfiltration.
OpenCVE Enrichment