Description
CVE-2026-97714
is a is a vulnerability in the authentication sub-system of Secure Access
servers prior to version 14.60. Attackers can send a malformed response during
authentication and cause a persistent denial of service.
Published: 2026-10-07
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows an attacker to trigger a persistent denial of service by sending a malformed response during the authentication process. The flaw occurs entirely within the authentication subsystem of Secure Access servers and can cause the service to become unresponsive once the malformed data is processed. The primary impact is a loss of availability for the authentication service, potentially cascading to downstream services relying on authentication, and leading to service disruption without any requirement for user credentials.

Affected Systems

Absolute Security’s Secure Access product is affected in all releases prior to version 14.60. The issue is specific to the authentication component of the server and does not affect other modules of the product.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity vulnerability. While an EPSS score is not provided, the lack of availability does not mean low exploitation probability; the flaw can be triggered remotely by an attacker with network access to the authentication interface. Because the vulnerability is listed as not in KEV, there is no evidence of known active exploitation, yet the high severity and ability to cause service outage make it a significant risk to availability.

Generated by OpenCVE AI on October 7, 2026 at 20:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Secure Access to version 14.60 or later, which contains the patch that validates authentication responses correctly.
  • Restrict network access to the authentication service by limiting it to trusted hosts or implementing firewall rules, thereby reducing the window for attackers to send malformed responses.
  • Implement monitoring or rate‑limiting on authentication requests to detect abnormal traffic patterns and automatically restart the service if it becomes unresponsive.

Generated by OpenCVE AI on October 7, 2026 at 20:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-400

Wed, 07 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description CVE-2026-97714 is a is a vulnerability in the authentication sub-system of Secure Access servers prior to version 14.60. Attackers can send a malformed response during authentication and cause a persistent denial of service.
Title Denial of service vulnerability in Secure Access
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-10-07T20:36:26.296Z

Reserved: 2026-09-24T22:30:33.466Z

Link: CVE-2026-97714

cve-icon Vulnrichment

Updated: 2026-10-07T20:36:22.315Z

cve-icon NVD

Status : Received

Published: 2026-10-07T20:17:15.893

Modified: 2026-10-07T21:17:23.000

Link: CVE-2026-97714

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T20:45:07Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-400

    Uncontrolled Resource Consumption