Impact
CVE-2026-55402 is an out‑of‑bounds read flaw in Secure Access servers. An attacker positioned between a client and the server can send specially crafted data that causes the server to read beyond the bounds of an internal buffer, resulting in a persistent denial of service. The vendor documentation does not mention code execution, data disclosure, or any other impact beyond service disruption; the denial of service is confined to the affected server.
Affected Systems
Absolute Security’s Secure Access servers running versions prior to 14.57 are affected. No other vendors or product lines are referenced in the CNA data.
Risk and Exploitability
The CVSS score of 8.7 classifies the issue as high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits to date. The attack requires an attacker to be in a man‑in‑the‑middle position, implying network‑level control or interception capability. If such conditions exist, the attacker can repeatedly trigger the crash, keeping the service unavailable, but the impact is limited to the targeted server and does not affect other systems.
OpenCVE Enrichment