CVE-2026-45206

7.8

Trend Micro · TrendAI Apex One

An origin validation vulnerability in the TrendAI Apex One agent allows for local privilege escalation.

Executive summary

A privilege escalation vulnerability in the TrendAI Apex One agent, caused by improper origin validation, requires immediate patching to prevent unauthorized administrative access.

Vulnerability

This vulnerability involves an origin validation error that allows an authenticated local user to perform actions outside of their intended privilege level, resulting in successful privilege escalation.

Business impact

The CVSS score of 7.8 underscores the high business impact of this vulnerability. If left unpatched, an attacker with local access can bypass security controls to gain elevated privileges, significantly increasing the risk of data breaches and persistent unauthorized access to critical infrastructure.

Remediation

Immediate Action: Update all affected TrendAI Apex One agents to version 14.0.0.17079 for on-premises or 14.0.20731 for SaaS deployments.

Proactive Monitoring: Monitor for unusual activity involving agent-related processes or indicators of local privilege escalation attempts.

Compensating Controls: Ensure that systems are configured with the principle of least privilege to minimize the potential impact should an attacker attempt to exploit local vulnerabilities.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Administrators must prioritize the deployment of the identified updates. Given the nature of the flaw, failing to patch leaves endpoints vulnerable to local attackers seeking to gain administrative control.

More Trend Micro CVEs