Relative Path Traversal in Apex One - CVE-2026-34926
Published: May 22, 2026
Apex One
Detailed vulnerability description
The vulnerability allows a local privileged user to inject malicious code for deployment to agents.
The vulnerability exists due to path traversal in the Apex One server when accessing server directories. A local privileged user can modify a key table on the server to inject malicious code for deployment to agents.
This issue is only exploitable on on-premise Apex One installations.
Note, the vulnerability is being actively exploited in the wild.