Description
CVE-2026-97715 is
a vulnerability in the client registration process of Secure Access servers
prior to version 14.60. Authenticated attackers can pass malformed data to the
server and cause a persistent denial of service.
Published: 2026-10-07
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

Vulnerable versions of Secure Access allow an authenticated attacker to send malformed data during client registration, which triggers a persistent denial of service by causing the server to crash or become unresponsive. The issue stems from insufficient input validation, falling under CWE‑20, and results in loss of availability for the affected service.

Affected Systems

Absolute Security’s Secure Access product is affected in all releases prior to version 14.60. Administrators need to verify that any deployed instances are running 14.60 or later to avoid exploitation.

Risk and Exploitability

The CVSS score is 7.1, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, so the likelihood of exploitation in the wild cannot be precisely quantified. As the flaw requires authenticated access, attackers must possess valid credentials or compromise an account to submit the malformed data; once they do, the denial of service is persistent and can affect all users of the Secure Access service.

Generated by OpenCVE AI on October 7, 2026 at 20:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Secure Access to version 14.60 or later to apply the vendor-supplied fix.
  • If an upgrade cannot occur immediately, restrict or temporarily disable the client registration feature for non-essential users while the patch is deployed.
  • Apply network-level controls, such as firewall rules or segmentation, to limit exposure of the Secure Access service to trusted hosts, thereby reducing the attack surface for authenticated users.

Generated by OpenCVE AI on October 7, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-400

Wed, 07 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description CVE-2026-97715 is a vulnerability in the client registration process of Secure Access servers prior to version 14.60. Authenticated attackers can pass malformed data to the server and cause a persistent denial of service.
Title Denial of Service in Absolute Secure Access
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-10-07T20:38:18.611Z

Reserved: 2026-09-24T22:30:33.466Z

Link: CVE-2026-97715

cve-icon Vulnrichment

Updated: 2026-10-07T20:38:14.610Z

cve-icon NVD

Status : Received

Published: 2026-10-07T20:17:16.053

Modified: 2026-10-07T21:17:23.137

Link: CVE-2026-97715

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T20:30:13Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-400

    Uncontrolled Resource Consumption