CVE-2026-40145CWE-1220

CVE-2026-40145

published August 17, 2026

CVSS
7.1
EPSS
0%
Percentile
2.6
In the wild
Unconfirmed
What it is

A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protection controls. Under certain conditions, the protections applied to the utility process may not be enforced as intended.

The record
Technical detail
CVSS
7.1 · NONE
CVSS v4.0
7.1 · CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00127 · 2.6th percentile
Weakness
CWE-1220 · Insufficient Granularity of Access Control
Published
2026-08-17T21:16Z
References (2)
EPSS history
Timeline
  • 17 AUG 16:29Z
    Control protections bypass in BeyondTrust Endpoint Privilege Management (Windows deployment) support utility
    cvelistv5