VYPR
advisoryPublished Jul 29, 2026· 1 source

TrendAI Vision One Service Gateway Vulnerability Exposes Sensitive Data

A critical information disclosure vulnerability in TrendAI Vision One Service Gateway, tracked as CVE-2025-71386, allows authenticated remote attackers to expose sensitive system data.

The Zero Day Initiative (ZDI) has publicly disclosed a significant information disclosure vulnerability affecting TrendAI Vision One Service Gateway. Identified as CVE-2025-71386, this flaw permits authenticated remote attackers to access and exfiltrate sensitive data stored within the system's log files.

The vulnerability resides within the Service Gateway module of TrendAI Vision One. The core issue stems from the insecure storage of sensitive information directly within log files. This design oversight means that an attacker who gains authenticated access to the system can exploit this weakness to read these log files and obtain confidential data.

Exploitation of CVE-2025-71386 requires an attacker to first possess valid user credentials for the affected TrendAI Vision One installation. Once authenticated, the attacker can then trigger the vulnerability to read the log files, potentially revealing a wide range of sensitive information. The CVSS score for this vulnerability is rated at 7.7, classifying it as High severity, underscoring the potential impact on affected organizations.

Trend Micro, the vendor behind TrendAI Vision One, has acknowledged the vulnerability and has released security updates to address the issue. Users are strongly advised to apply these patches as soon as possible to mitigate the risk of exploitation. Further details on the remediation steps can be found on Trend Micro's support portal.

The disclosure timeline indicates that the vulnerability was initially reported to Trend Micro on September 17, 2025. Following a coordinated disclosure process, the advisory was publicly released on July 29, 2026, with an update to the advisory on the same day. This extended period allowed Trend Micro ample time to develop and distribute a fix.

This vulnerability was discovered and reported by Hugo LECLERCQ. The Zero Day Initiative, a program operated by Trend Micro's Zero Day Initiative, plays a crucial role in coordinating with vendors to ensure vulnerabilities are responsibly disclosed and patched before public release.

The implications of this vulnerability are significant for organizations relying on TrendAI Vision One for their security operations. Exposure of sensitive data could lead to further compromise, including unauthorized access to other systems, data breaches, and reputational damage. The requirement for authentication limits the attack surface to those who can already gain some level of access, but it does not diminish the severity of the potential data exposure.

This incident highlights the ongoing challenge of securing complex security platforms and the critical importance of secure logging practices. Organizations must ensure that sensitive information is never written to accessible log files and that authentication mechanisms are robust to prevent unauthorized access.

Synthesized by Vypr AI