Time-of-check Time-of-use (TOCTOU) Race Condition in Apex One - CVE-2026-45208
Published: May 22, 2026
Apex One
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to time-of-check time-of-use race condition in the Apex One/SEP agent when handling file or resource access. A local user can win the race condition to escalate privileges.
Exploitation requires the ability to execute low-privileged code on the target system.