SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2026-40952

Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a non-default location.

HIGH 8.5EPSS 0.14%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.14%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a non-default location.

CVSS 4.0
8.5 HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.14% probability · 3th percentile
CISA KEV
Not listed
Weakness
CWE-276
Affected
absolute/secure access
Source
SecurityResponse@netmotionsoftware.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.