Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-34926

Опубликовано: 21 мая 2026
Источник: nvd
CVSS3: 6.7
EPSS Средний

Описание

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.

This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:*
Версия до 14.0.0.17079 (исключая)
cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:*
Версия до 14.0.20731 (исключая)

EPSS

Процентиль: 96%
0.12682
Средний

6.7 Medium

CVSS3

Дефекты

CWE-23

Связанные уязвимости

CVSS3: 6.7
github
3 месяца назад

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.

CVSS3: 6.7
fstec
3 месяца назад

Уязвимость антивирусного программного средства Trend Micro Apex One, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 96%
0.12682
Средний

6.7 Medium

CVSS3

Дефекты

CWE-23