CVE-2026-40145 PUBLISHED

Control protections bypass in BeyondTrust Endpoint Privilege Management (Windows deployment) support utility

Assigner: BT
Reserved: 09.04.2026 Published: 17.08.2026 Updated: 17.08.2026

A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protection controls. Under certain conditions, the protections applied to the utility process may not be enforced as intended.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor BeyondTrust
Product Endpoint Privilege Management (Windows deployment)
Versions Default: unaffected
  • affected from 0 to 26.1.2 (excl.)

References

Problem Types

  • CWE-1220 Insufficient granularity of access control CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs