Memory-Corruption Vulnerability in BeyondTrust Endpoint Privilege Management
CVE-2026-40144

7.3HIGH

Key Information:

Vendor
CVE Published:
17 August 2026

What is CVE-2026-40144?

A vulnerability in a kernel-mode component of BeyondTrust Endpoint Privilege Management for Windows allows for memory corruption due to insufficient input validation. This flaw can lead to accessing memory outside its intended bounds, potentially compromising system stability and security. Users are advised to update to version 26.1.2 or later to mitigate this risk.

Affected Version(s)

Endpoint Privilege Management (Windows deployments) Windows 0 < 26.1.2

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.