CVE-2026-40145: Control protections bypass in BeyondTrust Endpoint Privilege Management (Windows deployment) support utility
A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protection controls. Under certain conditions, the protections applied to the utility process may not be enforced as intended.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40145?
CVE-2026-40145 has a risk score of 44, indicating a moderate severity level.
How do I fix CVE-2026-40145?
To remediate CVE-2026-40145, ensure you apply the latest security patch provided by BeyondTrust for the Endpoint Privilege Management support utility.
What systems are affected by CVE-2026-40145?
CVE-2026-40145 specifically affects the BeyondTrust Endpoint Privilege Management (Windows deployment) support utility.
What are the potential consequences of CVE-2026-40145?
Exploitation of CVE-2026-40145 could lead to bypassed tamper protection controls, allowing unauthorized alterations to the support utility.
When was CVE-2026-40145 published?
CVE-2026-40145 was published on August 17, 2026.