Impact
CVE‑2026‑55400 is an integer underflow in Secure Access servers that can be triggered by a crafted packet sent from an authenticated session. The underflow occurs in an internal arithmetic operation, causing the server to stall and enter an infinite loop, which ultimately results in a persistent denial of service. The flaw does not leak data or enable code execution, but it continuously interrupts availability for all users on the affected instance.
Affected Systems
The vulnerability affects Absolute Security’s Secure Access product on versions prior to 14.57, specifically when the server is running a non‑default configuration. Any instance of Secure Access older than 14.57 that operates with such a configuration is susceptible.
Risk and Exploitability
The CVSS score of 6.0 indicates a moderate potential impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited current exploitation awareness. Attackers must possess an authenticated session and send specially crafted traffic; the flaw is triggered in a non‑default configuration, so a direct, authenticated network attack that can reach the server is required. The risk level is moderate, with exposure limited to availability rather than confidentiality or integrity.
OpenCVE Enrichment