What is CVE-2026-40144?
This is a memory corruption vulnerability in a kernel-mode component of BeyondTrust Endpoint Privilege Management for Windows deployments prior to version 26.1.2. The issue stems from insufficient input validation, potentially allowing memory access outside intended bounds. Affected systems should be updated to version 26.1.2 immediately to mitigate the risk.
Azərbaycanca: Bu, BeyondTrust Endpoint Privilege Management-in Windows versiyalarında kernel rejimində işləyən komponentdə aşkarlanmış yaddaş korrupsiyası zəifliyidir. 26.1.2 versiyasından əvvəlki quraşdırmaları təsir edir və zəifliyin səbəbi komponent tərəfindən işlənən giriş məlumatlarının kifayət qədər yoxlanılmamasıdır, nəticədə yaddaşa nəzərdə tutulmuş sərhədlərdən kənarda giriş baş verə bilər. Bu problemi aradan qaldırmaq üçün dərhal 26.1.2 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Which BeyondTrust product is affected by CVE-2026-40144?
BeyondTrust Endpoint Privilege Management for Windows.
To which version should one upgrade to fix this vulnerability?
An immediate update to version 26.1.2 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.