ZDI-CAN-27959: ZDI-26-320: TrendAI Vision One Security Agent Origin Validation Error Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Vision One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-34927.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27959?
The severity of ZDI-CAN-27959 is rated at 46, indicating a significant risk for exploitation.
How do I fix ZDI-CAN-27959?
To mitigate ZDI-CAN-27959, ensure that you apply the latest patches released by Trend Micro for TrendAI Vision One Security Agent.
What systems are affected by ZDI-CAN-27959?
ZDI-CAN-27959 affects installations of Trend Micro TrendAI Vision One Security Agent.
Who can exploit ZDI-CAN-27959?
Local attackers with the ability to execute low-privileged code on the target system can exploit ZDI-CAN-27959.
What type of vulnerability is ZDI-CAN-27959?
ZDI-CAN-27959 is classified as a local privilege escalation vulnerability.