Junglewise Threat Intelligence

CVE-2026-41993: TXOne Networks SafePortAgent and StellarProtect access control bypass in Removable Media Validation

CVE-2026-41993 · Severity: medium · CVSS 4.4 · Published 2026-07-17

Executive brief

A security flaw in TXOne Networks' endpoint protection software could allow a user with administrative access to bypass file lockdown protections. This vulnerability specifically affects the system that validates removable media like USB drives, potentially allowing unauthorized files to be transferred onto a protected device. While the attacker needs high-level local access, this bypass undermines the integrity of the 'lockdown' security feature designed to prevent unauthorized data movement.

Technical details

An improper access control vulnerability exists in the Removable Media Validation function of TXOne SafePortAgent and StellarProtect. A local attacker with high privileges (Administrator) can bypass the file lockdown mechanism to transfer unauthorized files from removable media to the host system. The exploit requires the attacker to have pre-positioned unauthorized files on the media. The issue is resolved in SafePortAgent version 3.2.5024 and StellarProtect version 5.0.1083.

Affected products

  • TXOne Networks SafePortAgent before 3.2.5024
  • TXOne Networks StellarProtect 3.2.4011 to 5.0.1083

Timeline

  • 2026-07-15: advisory: TXOne Networks published the security advisory.
  • 2026-07-17: disclosed: CVE published to the NVD.

References