CVE Watchtower


← Back to CVE List

CVE-2026-34926NVD

Vulnerability Summary

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.


This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
Severity Level
MEDIUM(6.7)
Published Date
May 21, 2026
Last Modified
Jul 23, 2026
Exploitation Status
ACTIVE
EPSS Score (30-Day)
12.68%Probability
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v3.1 Base Metrics
Attack VectorLocal
Attack ComplexityHigh
Privileges RequiredHigh
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityLow
AvailabilityLow