CVE-2026-34930

7.8

Trend Micro · TrendAI Apex One

An origin validation vulnerability in the TrendAI Apex One agent allows a local authenticated attacker to escalate privileges on affected installations.

Executive summary

A privilege escalation vulnerability in the TrendAI Apex One agent poses a significant risk of unauthorized system-level access by local attackers.

Vulnerability

The software suffers from an origin validation error (CWE-346). A local attacker with low privileges can exploit this flaw to execute actions with higher privileges than authorized.

Business impact

Successful exploitation of this vulnerability allows a local attacker to achieve privilege escalation, potentially resulting in full system compromise. With a CVSS score of 7.8, this vulnerability is classified as High, reflecting the significant impact on system integrity and confidentiality when an attacker gains elevated control over the security agent.

Remediation

Immediate Action: Update TrendAI Apex One to version 14.0.0.17079 or apply the latest service update for SaaS deployments as directed by Trend Micro.

Proactive Monitoring: Review system logs for suspicious process execution or unauthorized attempts to interact with security agent services.

Compensating Controls: Ensure strict adherence to the principle of least privilege for all local user accounts to limit the potential impact of local exploitation.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of privilege escalation vulnerabilities, organizations should prioritize patching affected endpoints. Apply the vendor-supplied updates immediately to prevent local attackers from abusing the agent's elevated permissions.

More Trend Micro CVEs