{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-40952","assignerOrgId":"b6533044-ea05-4482-8458-7bddeca0d079","state":"PUBLISHED","assignerShortName":"Absolute","dateReserved":"2026-04-16T00:19:03.573Z","datePublished":"2026-07-15T19:32:58.728Z","dateUpdated":"2026-07-16T13:06:21.115Z"},"containers":{"cna":{"providerMetadata":{"orgId":"b6533044-ea05-4482-8458-7bddeca0d079","shortName":"Absolute","dateUpdated":"2026-07-15T19:32:58.728Z"},"title":"Privilge misconfiguration in Secure Access installers","affected":[{"vendor":"Absolute Security","product":"Secure Access","versions":[{"status":"affected","version":"0","lessThan":"14.55","versionType":"server"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"CVE-2026-40952 is a privilege misconfiguration\nin the Secure Access installer for the Windows client and server prior to\nversion 14.55. Attackers with local access to the client or server can use it\nto elevate privileges to Administrator when Secure Access is installed in a\nnon-default location.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>CVE-2026-40952 is a privilege misconfiguration\nin the Secure Access installer for the Windows client and server prior to\nversion 14.55. Attackers with local access to the client or server can use it\nto elevate privileges to Administrator when Secure Access is installed in a\nnon-default location. </p>"}]}],"references":[{"url":"https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-40952"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"HIGH","baseScore":8.5,"vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N"}}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.2"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-276","lang":"en","description":"CWE-276 Incorrect Default Permissions"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-16T13:05:54.727165Z","id":"CVE-2026-40952","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-16T13:06:21.115Z"}}]}}