CVE-2026-40145
7.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protection controls. Under certain conditions, the protections applied to the utility process may not be enforced as intended.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| BeyondTrust | Endpoint Privilege Management (Windows deployment) | 0 < 26.1.2 | affected |
Weaknesses
- CWE-1220: CWE-1220 Insufficient granularity of access control
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-40145
- https://www.beyondtrust.com/trust-center/security-advisories/bt26-04
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.