CVE-2026-55398: Memory management vulnerability in Secure Access clients
Published Jul 15, 2026
·Updated
CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server.
Affected Software
2 affected components
SailPoint Secure Access<14.55
Absolute Secure Access<14.55
Event History
Jul 15, 2026
CVE Published
via MITRE·08:17 PM
Data Sourced
via MITRE·08:17 PM
Description
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-55398?
CVE-2026-55398 has a medium severity rating of 6.9 according to the CVSS score.
2
How do I fix CVE-2026-55398?
To fix CVE-2026-55398, update all Secure Access clients and servers to version 14.55 or higher.
3
What is the impact of CVE-2026-55398?
CVE-2026-55398 can allow attackers with control over the tunnel protocol to perform a non-persistent DoS against the server.
4
What types of software are affected by CVE-2026-55398?
CVE-2026-55398 affects SailPoint Secure Access and Absolute Secure Access prior to version 14.55.
5
Is CVE-2026-55398 a buffer overflow vulnerability?
Yes, CVE-2026-55398 is categorized as a buffer overflow vulnerability.