CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure
Access Windows client prior to 14.50. Attackers with local control of
the Windows client can send malformed data to an API and elevate their
level of privilege to system.
References
| Link | Resource |
|---|---|
| https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-33451 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
05 May 2026, 02:31
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| CPE | cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| First Time |
Microsoft
Absolute secure Access Absolute Microsoft windows |
|
| References | () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-33451 - Vendor Advisory |
01 May 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-125 |
30 Apr 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-30 21:16
Updated : 2026-05-05 02:31
NVD link : CVE-2026-33451
Mitre link : CVE-2026-33451
CVE.ORG link : CVE-2026-33451
JSON object : View
Products Affected
absolute
- secure_access
microsoft
- windows
CWE
CWE-125
Out-of-bounds Read
