CVE-2026-55401 is a null dereference vulnerability on the load-balancing
sub-system of Secure Access servers prior to 14.57. Attackers can send
an unauthenticated packet to a Secure Access server with load balancing
enabled, which results in the internal load balancer crashing. After a
successful attack, the Secure Access server is still able to accept
connections and is still able to issue a failover to connected clients. https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Null Dereference Vulnerability in Secure Access Load Balancer | |
| Weaknesses | CWE-476 |
Thu, 13 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which results in the internal load balancer crashing. After a successful attack, the Secure Access server is still able to accept connections and is still able to issue a failover to connected clients. https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Absolute
Published:
Updated: 2026-08-13T19:03:32.732Z
Reserved: 2026-06-16T21:26:37.698Z
Link: CVE-2026-55401
Updated: 2026-08-13T19:03:10.042Z
Status : Received
Published: 2026-08-13T16:18:07.867
Modified: 2026-08-13T20:17:22.870
Link: CVE-2026-55401
No data.
OpenCVE Enrichment
Updated: 2026-08-13T17:30:07Z