« Volver al listado

CVE-2026-34926

Estado: AnalizadaMedia (6.7)⚠ Explotación activa

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.

This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CISA KEV — explotada activamente

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de traversal (CWE-23) que requiere acceso local con credenciales administrativas (AV:L, PR:H) para modificar tablas e inyectar código malicioso en agentes, permitiendo escalada de privilegios y ejecución remota en endpoints.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-34926",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-34926",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "active"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-22T03:55:44.534070Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@trendmicro.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.3,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@trendmicro.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:trendmicro:apexone_op:14.0.0.17079:*:*:*:*:*:*:*"
          ],
          "vendor": "Trend Micro, Inc.",
          "product": "TrendAI Apex One",
          "versions": [
            {
              "status": "affected",
              "version": "2019 (14.0)",
              "lessThan": "14.0.0.17079",
              "versionType": "semver"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:trendmicro:apexone_saas:14.0.0.20731:*:*:*:*:*:*:*"
          ],
          "vendor": "Trend Micro, Inc.",
          "product": "TrendAI Apex One as a Service",
          "versions": [
            {
              "status": "affected",
              "version": "SaaS",
              "lessThan": "14.0.20731",
              "versionType": "semver"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-21T14:16:45.213",
  "references": [
    {
      "url": "https://jvn.jp/en/vu/JVNVU90583059/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@trendmicro.com"
    },
    {
      "url": "https://success.trendmicro.com/en-US/solution/KA-0023430",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@trendmicro.com"
    },
    {
      "url": "https://success.trendmicro.com/ja-JP/solution/KA-0022974",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@trendmicro.com"
    },
    {
      "url": "https://www.jpcert.or.jp/english/at/2026/at260014.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@trendmicro.com"
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34926",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@trendmicro.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-23"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.\n\n\r\nThis vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de salto de directorio en el servidor Apex One (local) podría permitir a un atacante local preautenticado modificar una tabla clave en el servidor para inyectar código malicioso y desplegarlo en agentes de instalaciones afectadas.\n\nEsta vulnerabilidad solo es explotable en la versión local de Apex One y un atacante potencial debe tener acceso al servidor Apex One y haber obtenido ya credenciales administrativas para el servidor mediante algún otro método para explotar esta vulnerabilidad."
    }
  ],
  "lastModified": "2026-07-23T16:10:00.137",
  "cisaActionDue": "2026-06-04",
  "cisaExploitAdd": "2026-05-21",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F20657B-98A4-46BE-8481-12060262C850",
              "versionEndExcluding": "14.0.0.17079"
            },
            {
              "criteria": "cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "322053CC-D396-412E-9F81-7640FE9DB7BD",
              "versionEndExcluding": "14.0.20731"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@trendmicro.com",
  "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "cisaVulnerabilityName": "Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability"
}