Description
CVE-2026-55402 is an out of bounds read vulnerability in Secure Access
servers prior to version 14.57. Attackers with an ‘in the middle’
position can send specially crafted data to a server causing a
persistent denial of service.
Published: 2026-08-13
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE-2026-55402 is an out‑of‑bounds read flaw in Secure Access servers. An attacker positioned between a client and the server can send specially crafted data that causes the server to read beyond the bounds of an internal buffer, resulting in a persistent denial of service. The vendor documentation does not mention code execution, data disclosure, or any other impact beyond service disruption; the denial of service is confined to the affected server.

Affected Systems

Absolute Security’s Secure Access servers running versions prior to 14.57 are affected. No other vendors or product lines are referenced in the CNA data.

Risk and Exploitability

The CVSS score of 8.7 classifies the issue as high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits to date. The attack requires an attacker to be in a man‑in‑the‑middle position, implying network‑level control or interception capability. If such conditions exist, the attacker can repeatedly trigger the crash, keeping the service unavailable, but the impact is limited to the targeted server and does not affect other systems.

Generated by OpenCVE AI on August 13, 2026 at 17:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Secure Access installation to version 14.57 or later, which contains the fix for the out‑of‑bounds read.
  • Deploy network segmentation or enforce end‑to‑end encryption to prevent or detect a man‑in‑the‑middle position, such as using TLS inspection policies or strict authentication between clients and the server.
  • If an immediate upgrade is not possible, isolate the affected servers, monitor for sudden increases in dropped connections or crashes, and treat any sign of denial‑of‑service activity as a potential exploitation attempt.

Generated by OpenCVE AI on August 13, 2026 at 17:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read Causing Persistent Denial of Service in Secure Access Server
Weaknesses CWE-787

Thu, 13 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service.
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-08-13T16:16:22.160Z

Reserved: 2026-06-16T21:26:37.698Z

Link: CVE-2026-55402

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T17:17:24.630

Modified: 2026-08-13T17:17:24.630

Link: CVE-2026-55402

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T18:00:04Z

Weaknesses