ZDI-CAN-28122: ZDI-26-498: TrendAI Vision One Incorrect Privilege Assignment Privilege Escalation Vulnerability
Published Jul 29, 2026
·Updated
This vulnerability allows remote attackers to escalate privileges on affected installations of TrendAI Vision One. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2025-71387.
Affected Software
1 affected component
TrendAI Vision One
Event History
Jul 29, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker who is already authenticated to an affected TrendAI Vision One installation can exploit it to escalate privileges.
2
What impact should defenders expect from successful exploitation?
Successful exploitation allows privilege escalation on the affected installation. The advisory assigns the issue a CVSS score of 7.2.