Memory corruption vulnerability in Endpoint Privilege Management (Windows deployments)
Summary
| CVE | CVE-2026-40144 |
|---|---|
| State | PUBLISHED |
| Assigner | BT |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-17 16:16:56 UTC |
| Updated | 2026-08-18 15:04:46 UTC |
| Description | A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to version 26.1.2. Insufficient validation of input processed by the component may result in memory being accessed outside its intended bounds. |
Risk And Classification
Primary CVSS: v4.0 7.3 HIGH from 13061848-ea10-403d-bd75-c83a022c2891
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.001070000 probability, percentile 0.013110000 (date 2026-08-18)
Problem Types: CWE-125 | CWE-125 CWE-125 Out-of-bounds read
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 13061848-ea10-403d-bd75-c83a022c2891 | Secondary | 7.3 | HIGH | CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 7.3 | HIGH | CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
LocalAttack Complexity
HighAttack Requirements
NonePrivileges Required
LowUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
HighSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | BeyondTrust | Endpoint Privilege Management Windows Deployments | affected 26.1.2 cpe | Windows |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| nvd.nist.gov/vuln/detail/CVE-2026-40144 | 13061848-ea10-403d-bd75-c83a022c2891 | nvd.nist.gov | |
| www.beyondtrust.com/trust-center/security-advisories/bt26-04 | 13061848-ea10-403d-bd75-c83a022c2891 | www.beyondtrust.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.