CVE-2026-45539
7.4Microsoft · APM
Microsoft APM is vulnerable to improper link resolution and sensitive information exposure, potentially allowing unauthorized actors to access sensitive files.
Executive summary
Microsoft APM versions 0.5.4 through 0.12.x are affected by an information disclosure vulnerability that could allow unauthorized access to sensitive system files.
Vulnerability
This vulnerability involves Improper Link Resolution Before File Access (CWE-59) and Exposure of Sensitive Information (CWE-200). The vulnerability is exploitable by an unauthenticated remote attacker via a crafted interaction, as indicated by the CVSS vector AV:N/PR:N.
Business impact
Successful exploitation allows an attacker to bypass intended access controls and potentially read sensitive information from the host system. Given the CVSS score of 7.4, this represents a high-severity risk to confidentiality, which could lead to unauthorized data exfiltration or the compromise of credentials stored within the environment.
Remediation
Immediate Action: Update the Microsoft APM dependency manager to version 0.13.0 or later to incorporate the necessary security patches.
Proactive Monitoring: Monitor system logs for unusual file access patterns or attempts to resolve symlinks in directories managed by AI agent dependency processes.
Compensating Controls: Ensure that the service running the APM dependency manager operates with the principle of least privilege, restricting its file system access to the minimum necessary directories.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The vulnerability presents a clear risk to sensitive data confidentiality. Organizations utilizing Microsoft APM must prioritize upgrading to version 0.13.0 immediately. Failure to patch may expose the underlying system to unauthorized file disclosure, potentially facilitating further lateral movement within the network.