CVE-2026-40957

o   CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator.
Configurations

Configuration 1 (hide)

cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*

History

16 Jul 2026, 02:55

Type Values Removed Values Added
References () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-40957 - () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-40957 - Vendor Advisory
First Time Absolute secure Access
Absolute
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-1021
CPE cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*

15 Jul 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 20:17

Updated : 2026-07-16 14:16


NVD link : CVE-2026-40957

Mitre link : CVE-2026-40957

CVE.ORG link : CVE-2026-40957


JSON object : View

Products Affected

absolute

  • secure_access
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames