This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 21 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal in Trend Micro Apex One Server Enabling Local Code Deployment |
Thu, 21 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability. | |
| First Time appeared |
Trendmicro
Trendmicro apexone Op Trendmicro apexone Saas |
|
| Weaknesses | CWE-23 | |
| CPEs | cpe:2.3:a:trendmicro:apexone_op:14.0.0.17079:*:*:*:*:*:*:* cpe:2.3:a:trendmicro:apexone_saas:14.0.0.20731:*:*:*:*:*:*:* |
|
| Vendors & Products |
Trendmicro
Trendmicro apexone Op Trendmicro apexone Saas |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: trendmicro
Published:
Updated: 2026-05-21T13:50:42.508Z
Reserved: 2026-03-31T17:22:13.504Z
Link: CVE-2026-34926
Updated: 2026-05-21T13:50:37.989Z
Status : Undergoing Analysis
Published: 2026-05-21T14:16:45.213
Modified: 2026-05-21T15:05:28.023
Link: CVE-2026-34926
No data.
OpenCVE Enrichment
Updated: 2026-05-21T14:45:12Z