Junglewise Threat Intelligence

CVE-2026-40957: Absolute Security Secure Access clickjacking in server login page

CVE-2026-40957 · Severity: info · CVSS 6.1 · Published 2026-07-15

Technologies: Absolute Security Secure Access. Vendors: Absolute Security.

Executive brief

Absolute Security Secure Access, a tool used for secure remote connectivity, contains a vulnerability in its server login page. An attacker could trick an administrator into visiting a malicious website that embeds the legitimate login page within a hidden frame. This could allow the attacker to capture the administrator's login credentials, potentially leading to unauthorized access to the management console.

Technical details

A frameable content vulnerability (clickjacking) exists in the Absolute Security (formerly NetMotion) Secure Access server login page. The application fails to properly implement frame-busting headers or Content Security Policy (CSP) directives like 'frame-ancestors', allowing the login interface to be embedded in an iframe on a third-party domain. An attacker can leverage this by enticing an authenticated administrator to visit a malicious site, where the attacker can overlay transparent layers to capture keystrokes or credentials. This issue is resolved in Secure Access version 14.55.

Affected products

  • Absolute Security (formerly NetMotion) Secure Access prior to 14.55

Timeline

  • 2026-07-15: advisory
  • 2026-07-15: disclosed

References

Related threats