ZDI-CAN-28077: ZDI-26-322: TrendAI Vision One Security Agent Origin Validation Error Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Vision One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-34929.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28077?
ZDI-CAN-28077 has a CVSS rating of 46, indicating a significant security risk.
How do I fix ZDI-CAN-28077?
To fix ZDI-CAN-28077, upgrade to the latest version of Trend Micro TrendAI Vision One Security Agent as recommended by the vendor.
What type of vulnerability is ZDI-CAN-28077?
ZDI-CAN-28077 is a local privilege escalation vulnerability that allows attackers to gain elevated permissions.
What is required for an attacker to exploit ZDI-CAN-28077?
An attacker must have the ability to execute low-privileged code on the target system to exploit ZDI-CAN-28077.
Which software is affected by ZDI-CAN-28077?
The vulnerability affects Trend Micro TrendAI Vision One Security Agent installations.