CVE-2026-33450
Out of Bounds Read in Secure Access MacOS Client
Publication date: 2026-04-30
Last updated on: 2026-05-05
Assigner: NetMotion Software
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| absolute | secure_access | to 14.50 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-125 | The product reads data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2026-33450 is an out of bounds read vulnerability found in the Secure Access MacOS client versions prior to 14.50. This vulnerability allows an attacker who controls a modified server to send a specially crafted malformed packet to the client, which causes the client to perform an out of bounds read operation.
This malformed packet leads to a denial of service condition on the client, meaning the client application may crash or become unresponsive.
How can this vulnerability impact me? :
The primary impact of this vulnerability is a denial of service (DoS) on the Secure Access MacOS client. An attacker controlling a malicious or compromised server can exploit this flaw to disrupt the normal operation of the client by causing it to crash or become unresponsive.
This disruption could affect user productivity or availability of secure access services, but does not appear to allow for privilege escalation, data disclosure, or code execution based on the available information.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, you should update the Secure Access macOS client to version 14.50 or later, as versions prior to 14.50 are affected by this out-of-bounds read vulnerability.
Since the vulnerability is triggered by a malformed packet sent from a modified server, avoid connecting to untrusted or suspicious servers until the client is updated.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The provided information does not specify any impact of CVE-2026-33450 on compliance with common standards and regulations such as GDPR or HIPAA.