← Back

Secure Access

secure_access

Vendor: Absolute • 39 CVEs

CVEs (39)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Absolute
1Secure Access
May 4, 2026
Apr 30, 2026
6.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and trigger a denial of service...Show more
CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and trigger a denial of service.Show less
1Absolute
1Secure Access
May 5, 2026
Apr 30, 2026
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a specially crafted message to the server and cause a denial of servic...Show more
CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a specially crafted message to the server and cause a denial of serviceShow less
1Absolute
1Secure Access
May 5, 2026
Apr 30, 2026
6.8 MEDIUM· v4
4.4 MEDIUM· v3
N/A· v2
CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to trigger a denial of service.
1Absolute
1Secure Access
May 5, 2026
Apr 30, 2026
5.9 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
CVE-2026-33452 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to ‘blue screen’ the system.
1Absolute
1Secure Access
May 5, 2026
Apr 30, 2026
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and elevate their level...Show more
CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and elevate their level of privilege to system.Show less
1Absolute
1Secure Access
May 5, 2026
Apr 30, 2026
2.3 LOW· v4
5.5 MEDIUM· v3
N/A· v2
CVE-2026-33450 is an out of bounds read vulnerability in the Secure Access MacOS client prior to 14.50. Attackers with control of a modified server can send a malformed packet to the client causing a denial of service...Show more
CVE-2026-33450 is an out of bounds read vulnerability in the Secure Access MacOS client prior to 14.50. Attackers with control of a modified server can send a malformed packet to the client causing a denial of service.Show less
1Absolute
1Secure Access
May 5, 2026
Apr 30, 2026
2.3 LOW· v4
7.5 HIGH· v3
N/A· v2
CVE-2026-33449 is a buffer overflow in a message handling function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a cryptographically valid message to the client, over...Show more
CVE-2026-33449 is a buffer overflow in a message handling function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a cryptographically valid message to the client, overwriting a small portion of memory conceivably leading to a denial of service.Show less
1Absolute
1Secure Access
May 5, 2026
Apr 30, 2026
4.8 MEDIUM· v4
3.3 LOW· v3
N/A· v2
CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to 14.50. Attackers with control of a modified server can force the client to dump the contents of a sma...Show more
CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to 14.50. Attackers with control of a modified server can force the client to dump the contents of a small portion of memory to the log files potentially revealing secrets.Show less
1Absolute
1Secure Access
May 5, 2026
Apr 30, 2026
2.3 LOW· v4
9.8 CRITICAL· v3
N/A· v2
CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a special packet that can overwrite a small portion of...Show more
CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a special packet that can overwrite a small portion of memory conceivably leading to memory corruption or denial of service.Show less
1Absolute
1Secure Access
May 5, 2026
Apr 30, 2026
2.3 LOW· v4
9.8 CRITICAL· v3
N/A· v2
CVE-2026-33446 is a buffer overflow in the authentication sub-system of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a special packet that can overwrite a small portion...Show more
CVE-2026-33446 is a buffer overflow in the authentication sub-system of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a special packet that can overwrite a small portion of memory conceivably leading to memory corruption or a denial of service.Show less
1Absolute
1Secure Access
Feb 2, 2026
Jan 17, 2026
4.6 MEDIUM· v4
3.4 LOW· v3
N/A· v2
In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs under certain configurations. Any party with access to those logs could read the token and reuse it...Show more
In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs under certain configurations. Any party with access to those logs could read the token and reuse it to access an integrated system.Show less
1Absolute
1Secure Access
Feb 2, 2026
Jan 17, 2026
4.8 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
CVE-2026-0518 is a cross-site scripting vulnerability in versions of Secure Access prior to 14.20. An attacker with administrative privileges can interfere with another administrator’s use of the console.
1Absolute
1Secure Access
Feb 2, 2026
Jan 17, 2026
6.0 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
CVE-2026-0517 is a denial-of-service vulnerability in versions of Secure Access Server prior to 14.20. An attacker can send a specially crafted packet to a server and cause the server to crash
1Absolute
1Secure Access
Feb 10, 2026
Nov 4, 2025
6.0 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addressed in version 14.12. If a local networking policy is active, attackers on an adjacent network m...Show more
CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addressed in version 14.12. If a local networking policy is active, attackers on an adjacent network may be able to send a crafted packet and cause the client system to crash.Show less
1Absolute
1Secure Access
Dec 8, 2025
Nov 4, 2025
8.2 HIGH· v4
7.5 HIGH· v3
N/A· v2
CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and ca...Show more
CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and cause the server to crash.Show less
1Absolute
1Secure Access
Oct 16, 2025
Oct 2, 2025
4.6 MEDIUM· v4
3.4 LOW· v3
N/A· v2
CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with administrative access to the console can interfere with another administrator’s access to the console. Th...Show more
CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with administrative access to the console can interfere with another administrator’s access to the console. The attack complexity is low; there are no attack requirements. Privileges required to execute the attack are high and the victim must actively participate in the attack sequence. There is no impact to confidentiality or availability, there is a low impact to integrity.Show less
1Absolute
1Secure Access
Oct 16, 2025
Oct 2, 2025
5.5 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the console can redirect victims to an arbitrary URL. The attack complexity is low, attack requirements a...Show more
CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the console can redirect victims to an arbitrary URL. The attack complexity is low, attack requirements are present, no privileges are required, and users must actively participate in the attack. Impact to confidentiality is low and there is no impact to integrity or availability. There are high severity impacts to confidentiality, integrity, availability in subsequent systems.Show less
1Absolute
1Secure Access
Oct 16, 2025
Oct 2, 2025
1.8 LOW· v4
2.6 LOW· v3
N/A· v2
CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can publish a crafted test HTTP request originating from the Secure Access s...Show more
CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can publish a crafted test HTTP request originating from the Secure Access server. The attack complexity is high, there are no attack requirements, and user interaction is required. There is no direct impact to confidentiality, integrity, or availability. There is a low severity subsequent system impact to integrity.Show less
1Absolute
1Secure Access
Oct 16, 2025
Oct 2, 2025
5.3 MEDIUM· v4
3.3 LOW· v3
N/A· v2
CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to version 14.10. Attackers with access to the local file system can read the Java keystore file. The attac...Show more
CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to version 14.10. Attackers with access to the local file system can read the Java keystore file. The attack complexity is low, there are no attack requirements, the privileges required are low and no user interaction is required. Impact to confidentiality is low, there is no impact to integrity or availability.Show less
1Absolute
1Secure Access
Aug 5, 2025
Jul 31, 2025
5.1 MEDIUM· v4
3.8 LOW· v3
N/A· v2
CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions ca...Show more
CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly read or change other settings. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. The impact to system confidentiality and integrity is low, there is no impact to system availability.Show less