CVE-2026-40957 is a frameable content
vulnerability in the Secure Access server login page prior to 14.55. Attackers
with control of a malicious web site could use it to potentially steal
credentials from an unwary administrator.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 30 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Absolute
Absolute secure Access |
|
| Vendors & Products |
Absolute
Absolute secure Access |
Thu, 16 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1021 | |
| Metrics |
ssvc
|
Wed, 15 Jul 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator. | |
| Title | Frameable content vulnerability in the Secure Access server login page | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Absolute
Published:
Updated: 2026-07-16T13:16:38.543Z
Reserved: 2026-04-16T00:19:03.574Z
Link: CVE-2026-40957
Updated: 2026-07-16T13:16:35.010Z
Status : Modified
Published: 2026-07-15T20:17:00.210
Modified: 2026-07-16T14:16:51.930
Link: CVE-2026-40957
No data.
OpenCVE Enrichment
Updated: 2026-07-31T03:00:06Z