CVE-2026-34928
7.8Trend Micro · TrendAI Apex One
An origin validation vulnerability in the TrendAI Apex One agent allows a local authenticated attacker to escalate privileges on affected installations.
Executive summary
A privilege escalation vulnerability in the TrendAI Apex One agent poses a significant risk of unauthorized system-level access by local attackers.
Vulnerability
The software suffers from an origin validation error (CWE-346), enabling local attackers with low privileges to escalate their authority on the target system.
Business impact
With a CVSS score of 7.8, this vulnerability represents a high-risk security flaw. If exploited, an attacker could gain elevated privileges, undermining the host's security posture and potentially exposing sensitive data or enabling persistent unauthorized access.
Remediation
Immediate Action: Update TrendAI Apex One to version 14.0.0.17079 or apply the latest mandatory SaaS update released by Trend Micro.
Proactive Monitoring: Review access and audit logs for anomalous behavior related to service processes or attempts to bypass origin checks.
Compensating Controls: Maintain strong endpoint security policies and ensure that user accounts operate with the minimum necessary privileges to perform their functions.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for privilege escalation, immediate patching is recommended. Organizations should ensure that all instances of TrendAI Apex One are updated to the corrected versions to prevent local exploitation and maintain the integrity of their security infrastructure.