CVE-2026-34926: CWE-23: Relative Path Traversal in Trend Micro, Inc. TrendAI Apex One
CVE-2026-34926 is a directory traversal vulnerability in the on-premise version of Trend Micro's TrendAI Apex One server. It allows a pre-authenticated local attacker with administrative credentials on the server to modify a key table, potentially injecting malicious code that could be deployed to agents. Exploitation requires prior administrative access to the Apex One server and is limited to the on-premise deployment. The vulnerability has a CVSS score of 6.7, indicating medium severity. No official patch or remediation information is currently available, and no known exploits are reported in the wild.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-34926) involves a relative path traversal issue (CWE-23) in Trend Micro's TrendAI Apex One on-premise server version 2019 (14.0). A local attacker who already has administrative privileges on the server can exploit this flaw to modify a critical table on the server, enabling injection of malicious code that could be propagated to connected agents. The attack vector requires local access with high privileges and does not involve user interaction. The vulnerability affects only the on-premise version and is not applicable to cloud-hosted services.
Potential Impact
Successful exploitation could allow an attacker with administrative access to the Apex One server to inject malicious code into a key server table, which may then be deployed to agents managed by the server. This could lead to partial compromise of the managed environment, including potential confidentiality, integrity, and availability impacts. However, exploitation requires prior administrative access, limiting the attack scope. No known active exploits have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official remediation level or patch links are provided, administrators should monitor Trend Micro advisories for updates. Given that exploitation requires administrative access, ensuring strong access controls and credential protection on the Apex One server is recommended as a preventive measure.
CVE-2026-34926: CWE-23: Relative Path Traversal in Trend Micro, Inc. TrendAI Apex One
Description
CVE-2026-34926 is a directory traversal vulnerability in the on-premise version of Trend Micro's TrendAI Apex One server. It allows a pre-authenticated local attacker with administrative credentials on the server to modify a key table, potentially injecting malicious code that could be deployed to agents. Exploitation requires prior administrative access to the Apex One server and is limited to the on-premise deployment. The vulnerability has a CVSS score of 6.7, indicating medium severity. No official patch or remediation information is currently available, and no known exploits are reported in the wild.
CVSS v3.1
Score 6.7medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-34926) involves a relative path traversal issue (CWE-23) in Trend Micro's TrendAI Apex One on-premise server version 2019 (14.0). A local attacker who already has administrative privileges on the server can exploit this flaw to modify a critical table on the server, enabling injection of malicious code that could be propagated to connected agents. The attack vector requires local access with high privileges and does not involve user interaction. The vulnerability affects only the on-premise version and is not applicable to cloud-hosted services.
Potential Impact
Successful exploitation could allow an attacker with administrative access to the Apex One server to inject malicious code into a key server table, which may then be deployed to agents managed by the server. This could lead to partial compromise of the managed environment, including potential confidentiality, integrity, and availability impacts. However, exploitation requires prior administrative access, limiting the attack scope. No known active exploits have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official remediation level or patch links are provided, administrators should monitor Trend Micro advisories for updates. Given that exploitation requires administrative access, ensuring strong access controls and credential protection on the Apex One server is recommended as a preventive measure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- trendmicro
- Date Reserved
- 2026-03-31T17:22:13.504Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a0f0c4d7b8e1438d00559c0
Added to database: 05/21/2026, 13:44:45 UTC
Last enriched: 05/28/2026, 20:40:34 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 89
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.