Junglewise Threat Intelligence

CVE-2026-40952: Absolute Secure Access privilege escalation in Windows installer

CVE-2026-40952 · Severity: info · CVSS 8.5 · Published 2026-07-15

Technologies: Absolute Security Secure Access. Vendors: Absolute Security.

Executive brief

Absolute Secure Access, a tool used to provide secure remote connectivity for mobile workers, contains a flaw in its Windows installer. If the software was installed in a custom folder rather than the default location, a user with low-level access to the computer could exploit incorrect file permissions to gain full Administrator control. This could allow an unauthorized person to bypass security controls, access sensitive data, or install malicious software on the affected device.

Technical details

A privilege escalation vulnerability exists in the Absolute Secure Access (formerly NetMotion) installer for Windows client and server versions prior to 14.55. The flaw stems from a privilege misconfiguration (incorrect ACLs/permissions) that occurs when the software is installed in a non-default directory. A local attacker with low-privileged access can exploit these weak permissions to modify application files or configuration, leading to execution with SYSTEM or Administrator privileges. The vulnerability is addressed in version 14.55.

Affected products

  • Absolute Security (NetMotion) Secure Access prior to 14.55

Timeline

  • 2026-07-15: advisory
  • 2026-07-15: disclosed

References

Related threats