216.73.216.233

CVE-2026-34926

· Published 21/05/2026 14:16 · Modified 21/05/2026 20:16

Labels: CVE-2026-34926 2026-05-21CVE-2026-34926CWE-23[email protected]

Essential information

Published
21/05/2026 14:16
Modified
21/05/2026 20:16
Author
Creator
CVSS
6.7 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L

CVSS metrics

Description

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.

NVD status

Status
Undergoing Analysis — CVE is currently being analyzed by NVD staff, this process results in association of reference link tags, CVSS scores, CWE association, and CPE applicability statements.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
trendmicro / apex one cpe:2.3:a:trendmicro:apex_one:*:*:*:*:*:*:*:*

References