CVE-2026-34926 PUBLISHED

Assigner: trendmicro
Reserved: 31.03.2026 Published: 21.05.2026 Updated: 21.05.2026

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.

This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L
CVSS Score: 6.7

Product Status

Vendor Trend Micro, Inc.
Product TrendAI Apex One
Versions
  • affected from 2019 (14.0) to 14.0.0.17079 (excl.)
Vendor Trend Micro, Inc.
Product TrendAI Apex One as a Service
Versions
  • affected from SaaS to 14.0.20731 (excl.)

References

Problem Types