Description
CVE-2026-55400 is an integer underflow in Secure Access servers prior to
version 14.57. Attackers with an authenticated session can send
specially crafted traffic to a server in a non-default configuration and
cause a persistent denial of service.
Published: 2026-08-13
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE‑2026‑55400 is an integer underflow in Secure Access servers that can be triggered by a crafted packet sent from an authenticated session. The underflow occurs in an internal arithmetic operation, causing the server to stall and enter an infinite loop, which ultimately results in a persistent denial of service. The flaw does not leak data or enable code execution, but it continuously interrupts availability for all users on the affected instance.

Affected Systems

The vulnerability affects Absolute Security’s Secure Access product on versions prior to 14.57, specifically when the server is running a non‑default configuration. Any instance of Secure Access older than 14.57 that operates with such a configuration is susceptible.

Risk and Exploitability

The CVSS score of 6.0 indicates a moderate potential impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited current exploitation awareness. Attackers must possess an authenticated session and send specially crafted traffic; the flaw is triggered in a non‑default configuration, so a direct, authenticated network attack that can reach the server is required. The risk level is moderate, with exposure limited to availability rather than confidentiality or integrity.

Generated by OpenCVE AI on August 13, 2026 at 17:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch to Secure Access 14.57 or later to eliminate the integer underflow flaw.
  • Reconfigure affected servers to use the default configuration, reducing the attack surface for the underflow trigger.
  • Implement network access controls to restrict authenticated traffic to essential services, limiting the possibility of malicious packets reaching the vulnerable code path.

Generated by OpenCVE AI on August 13, 2026 at 17:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Underflow‑Based Persistent Denial of Service in Absolute Secure Access
Weaknesses CWE-190

Thu, 13 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially crafted traffic to a server in a non-default configuration and cause a persistent denial of service.
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-08-13T18:50:28.496Z

Reserved: 2026-06-16T21:26:37.698Z

Link: CVE-2026-55400

cve-icon Vulnrichment

Updated: 2026-08-13T18:50:11.252Z

cve-icon NVD

Status : Received

Published: 2026-08-13T16:18:07.720

Modified: 2026-08-13T19:17:23.603

Link: CVE-2026-55400

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T18:00:04Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound