CVE-2026-34926

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:*
cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:*

History

22 May 2026, 12:47

Type Values Removed Values Added
First Time Trendmicro
Trendmicro apex One
CPE cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:*
cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:*
References () https://jvn.jp/en/vu/JVNVU90583059/ - () https://jvn.jp/en/vu/JVNVU90583059/ - Third Party Advisory
References () https://success.trendmicro.com/en-US/solution/KA-0023430 - () https://success.trendmicro.com/en-US/solution/KA-0023430 - Vendor Advisory
References () https://success.trendmicro.com/ja-JP/solution/KA-0022974 - () https://success.trendmicro.com/ja-JP/solution/KA-0022974 - Vendor Advisory
References () https://www.jpcert.or.jp/english/at/2026/at260014.html - () https://www.jpcert.or.jp/english/at/2026/at260014.html - Third Party Advisory
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34926 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34926 - Third Party Advisory, US Government Resource

21 May 2026, 20:16

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34926 -

21 May 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-21 14:16

Updated : 2026-05-22 12:47


NVD link : CVE-2026-34926

Mitre link : CVE-2026-34926

CVE.ORG link : CVE-2026-34926


JSON object : View

Products Affected

trendmicro

  • apex_one
CWE
CWE-23

Relative Path Traversal