Executive brief
Absolute Security Secure Access is a remote access solution that allows employees to securely connect to corporate resources. A vulnerability in the publisher component allows a user with valid login credentials to overwhelm the system, causing a temporary service disruption. While the disruption is not permanent, it can prevent other legitimate users from accessing the network until the issue is resolved.
Technical details
A resource exhaustion vulnerability exists in the Absolute Security (formerly NetMotion) Secure Access publisher component in versions prior to 14.55. The flaw allows an authenticated attacker with valid tunnel credentials to trigger a non-persistent Denial of Service (DoS) condition. By consuming excessive system resources, the attacker can degrade or halt the publisher's ability to process legitimate traffic. The attack requires network reachability to the Secure Access tunnel and valid low-privileged user credentials. The issue is addressed in Secure Access version 14.55.
Affected products
- Absolute Security (NetMotion Software) Secure Access prior to 14.55
Timeline
- 2026-07-15: advisory: Advisory published by Absolute Security and NVD record created.
- 2026-07-15: patched: Fix available in version 14.55.