CVE-2026-45206
Privilege Escalation in Apex One/SEP Agent
Publication date: 2026-05-21
Last updated on: 2026-05-21
Assigner: Trend Micro, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| trendmicro | apex_one | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-346 | The product does not properly verify that the source of data or communication is valid. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an origin validation flaw in the Apex One/SEP agent that could allow a local attacker to escalate their privileges on affected systems. It requires the attacker to already have the ability to execute low-privileged code on the target system. The issue is related to a process protection communication mechanism and is similar to another vulnerability identified as CVE-2026-45207.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow an attacker with limited access to escalate their privileges, potentially gaining higher-level control over the affected system. This could lead to unauthorized access, modification, or disruption of system operations.