Junglewise Threat Intelligence

CVE-2026-40958: Absolute Security Secure Access input validation error in client tunnel protocol

CVE-2026-40958 · Severity: info · CVSS 2.3 · Published 2026-07-15

Technologies: Absolute Security Secure Access. Vendors: Absolute Security.

Executive brief

Absolute Security Secure Access (formerly NetMotion) is a VPN-like solution used to provide secure remote connectivity for mobile workforces. A vulnerability in the client software allows an attacker with deep technical control over the connection protocol to temporarily disrupt the service for a user. This results in a non-persistent denial-of-service, meaning the user's connection may drop or the application may crash, but no data is stolen or permanently lost.

Technical details

An input validation error exists in the Absolute Security Secure Access client (formerly NetMotion) tunnel protocol handling. An attacker who has achieved total control over the tunnel protocol and possesses intimate knowledge of its inner workings can exploit this flaw to trigger a non-persistent denial-of-service (DoS) against the client. The vulnerability is categorized as a low-severity issue because it requires significant preconditions (control over the protocol) and only impacts availability temporarily without affecting data confidentiality or integrity. The issue is resolved in Secure Access client version 14.55.

Affected products

  • Absolute Security (formerly NetMotion) Secure Access prior to 14.55

Timeline

  • 2026-07-15: disclosed
  • 2026-07-15: advisory

References

Related threats