CVE-2026-33451: Absolute Secure Access

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and elevate their level of privilege to system.

Affected products

  • Absolute Secure Access: before 14.50 (fixed in 14.50)

Published 2026-04-30. Last modified 2026-06-17.