← All Advisories

BeyondTrust Endpoint Privilege Management Kernel-Mode Component Fails to Validate Input Bounds, Allowing Out-of-Bounds Memory Access

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-40144

Key Details

CVECVE-2026-40144
CVSS Score / Version7.3 (High) / CVSS v4.0
Updated2026-08-18
Classified asCWE-125 (Out-of-bounds Read)

What to Know

A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to version 26.1.2. Insufficient validation of input processed by the component may result in memory being accessed outside its intended bounds. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-40144
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-40144