CVE-2026-40145

Summary

A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protection controls. Under certain conditions, the protections applied to the utility process may not be enforced as intended.

Affected Software

VendorProductVersion RangeStatus
BeyondTrustEndpoint Privilege Management (Windows deployment)0 < 26.1.2affected

Weaknesses

  • CWE-1220: CWE-1220 Insufficient granularity of access control

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References