Previously Impacted Product(s)
| Product | Platform | Language |
| TrendAI Vision One Service Gateway | SaaS | English |
Vulnerability Details
CVE-2025-71386: Information Disclosure Vulnerability
ZDI-CAN-28148
CVSS:3.1 – 9.9 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) at time of initial report
An information disclosure vulnerability previously discovered in TrendAI Vision One Service Gateway could allow a remote attacker to access sensitive information.
Please note: the key part of this vulnerability was promptly addressed on the backend in September 2025 after it was reported which effectively mitigated the risk of the vulnerability, and remnant updates to the client side were deployed in September 2025 and October 2025 monthly maintenance service updates (depending on service region).
CVE-2025-71387: Incorrect Privilege Assignment Privilege Escalation Vulnerability
ZDI-CAN-28122
CVSS:3.1 – 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) at time of initial report
A privilege escalation vulnerability previously discovered in TrendAI Vision One Service Gateway could allow a user with certain key roles to elevate their privileges.
Please note: this vulnerability was addressed and deployed in the December 2025 monthly maintenance service update (depending on service region).
Acknowledgement
TrendAI would like to thank the following individuals and/or organizations for responsibility disclosing these issues and working with us to help protect our customers:
- Hugo LECLERCQ working with TrendAI Zero Day Initiative (CVE-2025-71386)
- Xavier DANEST - Decathlon working with TrendAI Zero Day Initiative (CVE-2025-71387)
