Description
CVE-2026-97717
is a vulnerability in the proxy sub-system of Secure Access servers prior to
14.60. Authenticated attackers can send malformed data to the server and cause
a persistent denial of service.
Published: 2026-10-07
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the proxy sub‑system of Absolute Security’s Secure Access servers before version 14.60. An authenticated attacker can send malformed data that triggers a crash, resulting in a persistent denial‑of‑service state for all users of the affected server, thereby disrupting authentication services across the organization.

Affected Systems

Absolute Security’s Secure Access product, versions older than 14.60, is impacted. The advisory does not specify a patch version; therefore, any server with the cited build that permits authenticated access is at risk.

Risk and Exploitability

The CVSS score of 6.0 indicates moderate severity, but the EPSS score is unavailable, so exploitation likelihood cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog, suggesting limited evidence of active exploitation. Because the attack requires authenticated credentials, compromised or privileged accounts must be present for exploitation.

Generated by OpenCVE AI on October 8, 2026 at 01:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Secure Access to version 14.60 or later once a patch is released
  • Restrict or disable authentication for the proxy sub‑system to trusted accounts only
  • Implement monitoring and rate‑limiting to detect and mitigate repeated malformed requests

Generated by OpenCVE AI on October 8, 2026 at 01:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 00:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Wed, 07 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description CVE-2026-97717 is a vulnerability in the proxy sub-system of Secure Access servers prior to 14.60. Authenticated attackers can send malformed data to the server and cause a persistent denial of service.
Title Denial of Service in Absolute Secure Access
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-10-07T20:33:27.748Z

Reserved: 2026-09-24T22:30:33.466Z

Link: CVE-2026-97717

cve-icon Vulnrichment

Updated: 2026-10-07T20:33:22.641Z

cve-icon NVD

Status : Received

Published: 2026-10-07T20:17:16.347

Modified: 2026-10-07T21:17:23.403

Link: CVE-2026-97717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T01:30:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption