Null Dereference Vulnerability in Secure Access Servers by Absolute Software
CVE-2026-55401

6.9MEDIUM

Key Information:

Vendor
CVE Published:
13 August 2026

What is CVE-2026-55401?

The null dereference vulnerability in Secure Access servers prior to version 14.57 allows attackers to send unauthenticated packets to servers with load balancing enabled, potentially causing the internal load balancer to crash. Despite the failure in the load balancing subsystem, the affected Secure Access servers maintain their ability to accept connections and can issue failovers to connected clients, thereby posing significant risks to security and availability.

Affected Version(s)

Secure Access 0 < 14.57

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.