Incorrect Privilege Assignment in TrendAI Vision One Service Gateway - CVE-2025-71387
Published: August 3, 2026
Vulnerability identifier: #VU140819
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-71387
CWE-ID: CWE-266
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote administrator to escalate privileges on the system.
The vulnerability exists due to incorrect privilege assignment within the handling of Service Gateway registration, which leads to security restrictions bypass and privilege escalation.
Affected software
TrendAI Vision One Service Gateway
How to mitigate CVE-2025-71387
Install updates from vendor's website.