CVE-2026-33451

CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and elevate their level of privilege to system.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

05 May 2026, 02:31

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
First Time Microsoft
Absolute secure Access
Absolute
Microsoft windows
References () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-33451 - () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-33451 - Vendor Advisory

01 May 2026, 15:16

Type Values Removed Values Added
CWE CWE-125

30 Apr 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-30 21:16

Updated : 2026-05-05 02:31


NVD link : CVE-2026-33451

Mitre link : CVE-2026-33451

CVE.ORG link : CVE-2026-33451


JSON object : View

Products Affected

absolute

  • secure_access

microsoft

  • windows
CWE
CWE-125

Out-of-bounds Read