CVE-2026-45206
7.8Trend Micro · TrendAI Apex One
An origin validation vulnerability in the TrendAI Apex One agent allows for local privilege escalation.
Executive summary
A privilege escalation vulnerability in the TrendAI Apex One agent, caused by improper origin validation, requires immediate patching to prevent unauthorized administrative access.
Vulnerability
This vulnerability involves an origin validation error that allows an authenticated local user to perform actions outside of their intended privilege level, resulting in successful privilege escalation.
Business impact
The CVSS score of 7.8 underscores the high business impact of this vulnerability. If left unpatched, an attacker with local access can bypass security controls to gain elevated privileges, significantly increasing the risk of data breaches and persistent unauthorized access to critical infrastructure.
Remediation
Immediate Action: Update all affected TrendAI Apex One agents to version 14.0.0.17079 for on-premises or 14.0.20731 for SaaS deployments.
Proactive Monitoring: Monitor for unusual activity involving agent-related processes or indicators of local privilege escalation attempts.
Compensating Controls: Ensure that systems are configured with the principle of least privilege to minimize the potential impact should an attacker attempt to exploit local vulnerabilities.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Administrators must prioritize the deployment of the identified updates. Given the nature of the flaw, failing to patch leaves endpoints vulnerable to local attackers seeking to gain administrative control.