CVE-2026-40957
Modified Modified - Updated After Analysis

Frameable Content Vulnerability in Secure Access Server Login Page

Vulnerability report for CVE-2026-40957, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-15

Last updated on: 2026-07-16

Assigner: NetMotion Software

Description

oΒ Β  CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-15
Last Modified
2026-07-16
Generated
2026-08-05
AI Q&A
2026-07-16
EPSS Evaluated
2026-08-03
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
absolute secure_access to 14.55 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1021 The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page before version 14.55. Attackers with control of a malicious website can embed the login page in a frame to trick administrators into entering credentials.

Detection Guidance

To detect this vulnerability, inspect web pages for frameable content on the Secure Access server login page. Check if the login page can be embedded in an iframe by testing with browser developer tools or commands like curl to inspect HTTP headers for X-Frame-Options or Content-Security-Policy headers.

Impact Analysis

This vulnerability could allow attackers to steal administrator credentials through phishing or social engineering by embedding the login page in a malicious frame. Affected users may have their login details compromised.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by potentially exposing administrator credentials through phishing or social engineering attacks. Unauthorized access to credentials may lead to unauthorized data access or breaches, violating confidentiality requirements under these regulations.

Mitigation Strategies

Update the Secure Access server to version 14.55 or later to address the frameable content vulnerability. Monitor for suspicious login attempts or phishing activities targeting administrators.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-40957. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart