CVE-2026-45207
7.8Trend Micro · TrendAI Apex One
An origin validation error in the TrendAI Apex One agent allows a local attacker to escalate privileges.
Executive summary
A critical origin validation flaw in the TrendAI Apex One agent enables local attackers to escalate privileges on affected systems.
Vulnerability
The vulnerability stems from an origin validation error within the agent, which can be exploited by a local attacker with low privileges to perform unauthorized actions and escalate their system privileges.
Business impact
With a CVSS score of 7.8, this vulnerability presents a high risk to organizational security. An attacker who has already gained a foothold on a system with limited access could use this flaw to gain full control, potentially leading to unauthorized data access or widespread system disruption.
Remediation
Immediate Action: Apply the vendor-provided security updates: upgrade on-premises agents to 14.0.0.17079 and SaaS agents to 14.0.20731.
Proactive Monitoring: Review system audit logs for unauthorized attempts to interface with the Apex One agent or unexpected privilege escalation events.
Compensating Controls: Implement strict endpoint hardening and limit local user permissions to reduce the attack surface available to a local actor.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this issue necessitates prompt remediation. IT administrators should verify that all managed endpoints running TrendAI Apex One are updated to the specified versions to prevent privilege escalation.