CVE-2026-33451
Last modified
CVE-2026-33451 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and elevate their level of privilege to system.. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and elevate their level of privilege to system.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Absolute | Secure Access | < 14.50 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-33451?
How severe is CVE-2026-33451?
How do I fix CVE-2026-33451?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-33446CVE-2026-33446 is a buffer overflow in the authentication su…9.8
- CVE-2026-33447CVE-2026-33447 is a buffer overflow in a message parsing fun…9.8
- CVE-2026-33448CVE-2026-33448 is a format string vulnerability in the loggi…3.3
- CVE-2026-33449CVE-2026-33449 is a buffer overflow in a message handling fu…7.5
- CVE-2026-3345IBM Langflow Desktop <=1.8.4 Langflow could allow a remote a…6.5
- CVE-2026-33450CVE-2026-33450 is an out of bounds read vulnerability in the…5.5
- CVE-2026-33452CVE-2026-33452 is a buffer overflow vulnerability in the Sec…5.5
- CVE-2026-33453Improperly Controlled Modification of Dynamically-Determined…10
- CVE-2026-33454The Camel-Mail component is vulnerable to Camel message head…9.4
- CVE-2026-33455Livestatus injection in the monitoring quicksearch in Checkm…6.3
- CVE-2026-33456Livestatus injection in the notification test mode in Checkm…7.6
- CVE-2026-33457Livestatus injection in the prediction graph page in Checkmk…6.3
Are you affected by CVE-2026-33451?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
