Executive brief
Absolute Security Secure Access, a tool used for secure remote connectivity, contains a vulnerability in its server login page. An attacker could trick an administrator into visiting a malicious website that embeds the legitimate login page within a hidden frame. This could allow the attacker to capture the administrator's login credentials, potentially leading to unauthorized access to the management console.
Technical details
A frameable content vulnerability (clickjacking) exists in the Absolute Security (formerly NetMotion) Secure Access server login page. The application fails to properly implement frame-busting headers or Content Security Policy (CSP) directives like 'frame-ancestors', allowing the login interface to be embedded in an iframe on a third-party domain. An attacker can leverage this by enticing an authenticated administrator to visit a malicious site, where the attacker can overlay transparent layers to capture keystrokes or credentials. This issue is resolved in Secure Access version 14.55.
Affected products
- Absolute Security (formerly NetMotion) Secure Access prior to 14.55
Timeline
- 2026-07-15: advisory
- 2026-07-15: disclosed