BeyondTrust Windows EPM Vulnerabilities Allows Attackers to Escalate Privileges

August 19, 2026

BeyondTrust has disclosed two high-severity vulnerabilities in its Endpoint Privilege Management (EPM) product for Windows that could allow attackers with local access to elevate privileges or bypass anti-tamper controls.

Tracked as CVE-2026-40144 and CVE-2026-40145, the flaws affect all versions of BeyondTrust Endpoint Privilege Management (Windows Deployment) released before version 26.1.2. The company published the advisory, BT26-04, on August 17, 2026.

BeyondTrust said the vulnerabilities were discovered internally during security assessment activities using frontier AI models and proprietary testing harnesses. The company said it has found no evidence that either flaw was exploited before remediation.

The most serious vulnerability, CVE-2026-40144, has a CVSS v4 score of 7.3 and is classified as high severity. It is an out-of-bounds read issue, identified as CWE-125, in a kernel-mode component of BeyondTrust EPM for Windows.

The flaw exists because the affected kernel component does not sufficiently validate certain input. A local attacker with standard, non-administrative user privileges could potentially cause the component to access memory outside its intended bounds.

BeyondTrust Windows EPM Vulnerabilities

Successful exploitation could enable an attacker to corrupt kernel memory and execute arbitrary code in kernel mode. Since kernel-mode code has the highest privilege level in Windows, an attacker could potentially gain full control of the affected endpoint.

The vulnerability requires local access, meaning it cannot be directly exploited over the internet without another method of gaining a foothold on the system.

However, local privilege-escalation bugs are often valuable to attackers after they compromise a low-privileged user account via phishing, malware, stolen credentials, or another initial access technique.

The second flaw, CVE-2026-40145, carries a CVSS v4 score of 7.1. It is an insufficient access-control vulnerability, tracked as CWE-1220, involving an interaction between a BeyondTrust EPM support utility and the product’s anti-tamper protections.

Under specific conditions, protections applied to the support utility process may not be enforced as intended. An attacker who already has elevated privileges on an endpoint may be able to influence the utility and execute code outside the intended scope of EPM’s anti-tamper controls.

Unlike the first issue, CVE-2026-40145 requires an attacker to possess already elevated privileges, local access, and additional endpoint-specific preconditions.

While it does not provide an initial path to administrator access, it could help attackers weaken security controls once they have gained privileged access.

BeyondTrust has fixed both issues in Endpoint Privilege Management (Windows Deployment) version 26.1.2. Organizations using affected versions should upgrade endpoints to version 26.1.2 or later as soon as possible.

Security teams should also review systems for unusual local privilege escalation activity, unexpected kernel-level crashes, suspicious process behavior involving EPM support utilities, and attempts to disable or interfere with endpoint security controls.

The advisory highlights the importance of promptly patching privilege-management tools. These products often run with elevated permissions and enforce critical security boundaries, making vulnerabilities in their kernel components or anti-tamper mechanisms especially attractive to attackers.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Original article can be found here