← Vulnerability feed

Vulnerability record · CVE-2026-40952 · published 15 July 2026

CVE-2026-40952: Absolute secure access incorrect default permissions vulnerability

Absolute · Secure Access

CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a non-default location.

8.5 CVSS 4.0 High EPSS 0.14% · top 97.4% CWE-276 · Incorrect default permissions
8.5CVSS 4.0 base score
0.14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
16 Jul 2026Last modified by NVD

Description

CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a non-default location.

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-40952 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2026-55402Absolute secure access out-of-bounds read vulnerabilityCVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can…EPSS 0.40%8.7CVE-2026-33445Absolute secure access uncontrolled resource consumption vulnerabilityCVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total contro…EPSS 0.40%8.7CVE-2025-49080Absolute secure access vulnerabilityThere is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with network access to the server can ca…EPSS 0.37%8.5CVE-2026-33451Absolute secure access out-of-bounds read vulnerabilityCVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windo…EPSS 0.15%8.2CVE-2025-59595Absolute secure access improper input validation vulnerabilityCVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specia…EPSS 0.34%7.1CVE-2026-33443Absolute secure access uncontrolled resource consumption vulnerabilityCVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over t…EPSS 0.37%7.1CVE-2026-40950Absolute secure access stack-based buffer overflow vulnerabilityCVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a …EPSS 0.42%7.0CVE-2025-49083Absolute secure access deserialization of untrusted data vulnerabilityCVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. Attackers with …EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2026-40952), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.