6.7

CVE-2026-34926

Warnung
Medienbericht
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.


This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex One SwEdition on-premises SwPlatform windows Version < 14.0.0.17079
Trendmicro ≫ Apex One SwEdition saas SwPlatform windows Version < 14.0.20731

21.05.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

Schwachstelle

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.

Beschreibung

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 12.68% 0.957
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Trendmicro 6.7 0.8 5.3
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L
CWE-23 Relative Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
05.06.2026 12:44
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
05.06.2026 12:44
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
05.06.2026 12:43
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
05.06.2026 12:43
https://www.jpcert.or.jp/english/at/2026/at260014.html
Third Party Advisory
https://jvn.jp/en/vu/JVNVU90583059/
Third Party Advisory
https://success.trendmicro.com/en-US/solution/KA-0023430
Vendor Advisory
https://success.trendmicro.com/ja-JP/solution/KA-0022974
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34926
Third Party Advisory
US Government Resource