PT-2026-36175 · Unknown · Secure Access

Published

2026-04-30

·

Updated

2026-05-01

·

CVE-2026-33451

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Secure Access Windows client versions prior to 14.50
Description An arbitrary read/write issue exists where attackers with local control of the Windows client can send malformed data to an API to elevate their privileges to system level.
Recommendations Update to version 14.50 or later.

Fix

Related Identifiers

CVE-2026-33451

Affected Products

Secure Access