Insufficient Granularity of Access Control in Endpoint Privilege Management for Windows - CVE-2026-40145
Published: August 19, 2026
Vulnerability details
The vulnerability allows a local privileged user to bypass the product's anti-tamper protection.
The vulnerability exists due to insufficient granularity of access control in the interaction between a support utility and the agent's tamper protection controls when the utility process protections are not enforced as intended. A local privileged user can influence the support utility process to bypass the product's anti-tamper protection.
Exploitation requires local access, an existing elevated process context, and additional preconditions on the endpoint.