CVE-2026-40952
Last modified
CVE-2026-40952 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a non-default location.. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a non-default location.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Absolute | Secure Access | < 14.55 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-40952?
How severe is CVE-2026-40952?
How do I fix CVE-2026-40952?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-40946Oxia is a metadata store and coordination system. Prior to 0…9.2
- CVE-2026-40947Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, an…2.9
- CVE-2026-40948The Keycloak authentication manager in `apache-airflow-provi…5.4
- CVE-2026-40949CVE-2026-40949 is a buffer overflow vulnerability in the Sec…4.4
- CVE-2026-40950CVE-2026-40950 is a buffer overflow vulnerability in the Sec…6.5
- CVE-2026-40951CVE-2026-40951 is a memory corruption vulnerability on Secur…5.5
- CVE-2026-40953CVE-2026-40953 is a heap overflow in the certificate parsing…4.4
- CVE-2026-40954CVE-2026-40954 is an integer underflow vulnerability in the …3.7
- CVE-2026-40955CVE-2026-40955 is an integer underflow vulnerability in the …3.7
- CVE-2026-40956CVE-2026-40956 is a memory disclosure vulnerability in Secur…3.7
- CVE-2026-40957o CVE-2026-40957 is a frameable content vulnerability in t…7.5
- CVE-2026-40958CVE-2026-40958 is a input validation error in Secure Access …3.7
Are you affected by CVE-2026-40952?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
