CVE-2022-26871

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
29/03/2022
Last modified:
22/12/2025

Description

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:trendmicro:apex_central:2019:-:*:*:*:*:*:*
cpe:2.3:a:trendmicro:apex_one:-:*:*:*:*:saas:*:*