CVE-2026-33448
low
CVSS v3
3.3
CVSS v2
—
VIR risk
3.3
Description
CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to 14.50. Attackers with control of a modified server can force the client to dump the contents of a small portion of memory to the log files potentially revealing secrets.
Predictions
Exploit likelihood
34%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: SecurityResponse@netmotionsoftware.com — https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-33448
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| macos | - | not-affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| absolute | secure_access | {"endExcluding":"14.50"} | 14.50 |
References
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.