Description
CVE-2026-55401 is a null dereference vulnerability on the load-balancing
sub-system of Secure Access servers prior to 14.57. Attackers can send
an unauthenticated packet to a Secure Access server with load balancing
enabled, which results in the internal load balancer crashing. After a
successful attack, the Secure Access server is still able to accept
connections and is still able to issue a failover to connected clients. ‍ https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
Published: 2026-08-13
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability causes a null dereference in the load‑balancing subsystem of Absolute Security Secure Access servers when an unauthenticated packet is received. The resulting crash stops the internal load balancer, yet the server remains operational and can still hand off client connections, so the overall availability impact is moderate rather than a full shutdown.

Affected Systems

Absolute Security:Secure Access servers running any version prior to 14.57 and having load balancing enabled are affected; newer releases are not mentioned as vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. Attackers can exploit the flaw remotely without authentication by sending crafted packets to the load balancer. Because the EPSS score is not available and the vulnerability is not in CISA’s KEV catalog, the likelihood of widespread exploitation appears low, but the impact remains significant for affected environments.

Generated by OpenCVE AI on August 13, 2026 at 17:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Secure Access server to version 14.57 or later, which removes the null pointer dereference.
  • If upgrading is not immediately possible, restrict load‑balancing traffic to trusted sources or disable the load‑balancing feature until a fix is applied.
  • Monitor system logs for unexpected load‑balancer crashes and configure alerts for unusual activity.
  • Maintain redundancy and failover mechanisms to preserve service availability if a crash occurs.

Generated by OpenCVE AI on August 13, 2026 at 17:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Null Dereference Vulnerability in Secure Access Load Balancer
Weaknesses CWE-476

Thu, 13 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which results in the internal load balancer crashing. After a successful attack, the Secure Access server is still able to accept connections and is still able to issue a failover to connected clients. ‍ https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-08-13T16:11:08.672Z

Reserved: 2026-06-16T21:26:37.698Z

Link: CVE-2026-55401

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T16:18:07.867

Modified: 2026-08-13T16:18:07.867

Link: CVE-2026-55401

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T17:30:07Z

Weaknesses