CVE-2026-34927
7.8Trend Micro · TrendAI Apex One
An origin validation vulnerability in the TrendAI Apex One agent allows a local attacker to escalate privileges on affected installations.
Executive summary
A privilege escalation vulnerability in Trend Micro's Apex One agent poses a significant risk by allowing local attackers to gain elevated system permissions.
Vulnerability
This is an origin validation error (CWE-346) within the agent process. It allows a local, authenticated user with low privileges to bypass security checks and escalate their access level to that of the agent.
Business impact
The vulnerability carries a CVSS score of 7.8, reflecting its potential for total system compromise if exploited by a local user. Successful exploitation could allow an attacker to bypass security controls, install persistent malware, or exfiltrate sensitive data from the endpoint. This poses a high risk to organizational data integrity and overall system security.
Remediation
Immediate Action: Update TrendAI Apex One to version 14.0.0.17079 or later, or ensure the SaaS version is updated to build 14.0.20731 or later.
Proactive Monitoring: Review system logs for unusual process execution patterns or unexpected elevation of privileges occurring on endpoints managed by Apex One.
Compensating Controls: Implement strict Endpoint Detection and Response (EDR) policies to limit local user permissions and monitor for unauthorized attempts to interact with security agent processes.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for privilege escalation and full system compromise, administrators should prioritize patching all affected Apex One agents. Apply the vendor-provided updates immediately to close the validation gap and prevent unauthorized elevation of privileges within the environment.