ZDI-26-323: TrendAI Vision One Security Agent Origin Validation Error Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Vision One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-34930.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-323?
The severity of ZDI-26-323 is rated as 46, indicating a significant risk of privilege escalation.
How do I fix ZDI-26-323?
To mitigate ZDI-26-323, ensure that you apply the latest security updates provided by Trend Micro for the TrendAI Vision One Security Agent.
Who is impacted by ZDI-26-323?
Users and organizations running affected installations of TrendAI Vision One Security Agent are impacted by ZDI-26-323.
What can attackers do with ZDI-26-323?
Attackers can exploit ZDI-26-323 to escalate their privileges and execute unauthorized actions on the affected system.
Is exploitation of ZDI-26-323 easy?
Exploitation of ZDI-26-323 requires local access to execute low-privileged code, making it dependent on the attacker’s initial access level.