Description
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.


This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
Published: 2026-05-21
Score: 6.7 Medium
EPSS: 12.7% Moderate
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 24 Jun 2026 13:45:00 +0000

Type Values Removed Values Added
Title Directory Traversal Vulnerability Allows Local Admin to Deploy Malicious Code on Trend Micro Apex One On-Premises

Wed, 24 Jun 2026 08:45:00 +0000

Type Values Removed Values Added
Title Directory Traversal Vulnerability Allows Local Admin to Deploy Malicious Code on Trend Micro Apex One On-Premises

Wed, 24 Jun 2026 03:30:00 +0000

Type Values Removed Values Added
Title Directory Traversal Enables Local Admin to Alter Key Table for Agent Code Deployment

Tue, 23 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Title Directory Traversal Enables Local Admin to Alter Key Table for Agent Code Deployment

Tue, 23 Jun 2026 19:00:00 +0000

Type Values Removed Values Added
Title Directory Traversal Enables Local Key Table Manipulation in Trend Micro Apex One

Tue, 23 Jun 2026 16:00:00 +0000

Type Values Removed Values Added
Title Directory Traversal Enables Local Key Table Manipulation in Trend Micro Apex One

Tue, 26 May 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Trendmicro apex One
CPEs cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:*
cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:*
Vendors & Products Trendmicro apex One

Fri, 22 May 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 21 May 2026 21:15:00 +0000

Type Values Removed Values Added
Title Directory Traversal in Trend Micro Apex One Server Enabling Local Code Deployment

Thu, 21 May 2026 20:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 21 May 2026 19:00:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-05-21T00:00:00+00:00', 'dueDate': '2026-06-04T00:00:00+00:00'}


Thu, 21 May 2026 15:00:00 +0000

Type Values Removed Values Added
Title Directory Traversal in Trend Micro Apex One Server Enabling Local Code Deployment

Thu, 21 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 21 May 2026 13:45:00 +0000

Type Values Removed Values Added
Description A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
First Time appeared Trendmicro
Trendmicro apexone Op
Trendmicro apexone Saas
Weaknesses CWE-23
CPEs cpe:2.3:a:trendmicro:apexone_op:14.0.0.17079:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:apexone_saas:14.0.0.20731:*:*:*:*:*:*:*
Vendors & Products Trendmicro
Trendmicro apexone Op
Trendmicro apexone Saas
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L'}


Subscriptions

Trendmicro Apex One Apexone Op Apexone Saas
cve-icon MITRE

Status: PUBLISHED

Assigner: trendmicro

Published:

Updated: 2026-05-22T12:47:07.213Z

Reserved: 2026-03-31T17:22:13.504Z

Link: CVE-2026-34926

cve-icon Vulnrichment

Updated: 2026-05-21T13:50:37.989Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-21T14:16:45.213

Modified: 2026-06-17T10:39:49.727

Link: CVE-2026-34926

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-24T13:30:06Z

Weaknesses