{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-10-10T06:16:35.523","vulnerabilities":[{"cve":{"id":"CVE-2026-34926","sourceIdentifier":"security@trendmicro.com","published":"2026-05-21T14:16:45.213","lastModified":"2026-07-23T16:10:00.137","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.\n\n\r\nThis vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability."},{"lang":"es","value":"Una vulnerabilidad de salto de directorio en el servidor Apex One (local) podría permitir a un atacante local preautenticado modificar una tabla clave en el servidor para inyectar código malicioso y desplegarlo en agentes de instalaciones afectadas.\n\nEsta vulnerabilidad solo es explotable en la versión local de Apex One y un atacante potencial debe tener acceso al servidor Apex One y haber obtenido ya credenciales administrativas para el servidor mediante algún otro método para explotar esta vulnerabilidad."}],"affected":[{"source":"security@trendmicro.com","affectedData":[{"vendor":"Trend Micro, Inc.","product":"TrendAI Apex One","cpes":["cpe:2.3:a:trendmicro:apexone_op:14.0.0.17079:*:*:*:*:*:*:*"],"versions":[{"version":"2019 (14.0)","lessThan":"14.0.0.17079","versionType":"semver","status":"affected"}]},{"vendor":"Trend Micro, Inc.","product":"TrendAI Apex One as a Service","cpes":["cpe:2.3:a:trendmicro:apexone_saas:14.0.0.20731:*:*:*:*:*:*:*"],"versions":[{"version":"SaaS","lessThan":"14.0.20731","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@trendmicro.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":0.8,"impactScore":5.3}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-22T03:55:44.534070Z","id":"CVE-2026-34926","options":[{"exploitation":"active"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2026-05-21","cisaActionDue":"2026-06-04","cisaRequiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability","weaknesses":[{"source":"security@trendmicro.com","type":"Secondary","description":[{"lang":"en","value":"CWE-23"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:*","versionEndExcluding":"14.0.0.17079","matchCriteriaId":"6F20657B-98A4-46BE-8481-12060262C850"},{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:*","versionEndExcluding":"14.0.20731","matchCriteriaId":"322053CC-D396-412E-9F81-7640FE9DB7BD"}]}]}],"references":[{"url":"https://jvn.jp/en/vu/JVNVU90583059/","source":"security@trendmicro.com","tags":["Third Party Advisory"]},{"url":"https://success.trendmicro.com/en-US/solution/KA-0023430","source":"security@trendmicro.com","tags":["Vendor Advisory"]},{"url":"https://success.trendmicro.com/ja-JP/solution/KA-0022974","source":"security@trendmicro.com","tags":["Vendor Advisory"]},{"url":"https://www.jpcert.or.jp/english/at/2026/at260014.html","source":"security@trendmicro.com","tags":["Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34926","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Third Party Advisory","US Government Resource"]}]}}]}