CVE-2026-3991Disclosure

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 MP2 HF15, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 10 signals
  • Disclosure: 7 classified signals
  • Peaked 2d ago at 5 mentions (2026-04-02); latest day: 1
  • 11 total mentions across 5 days

Deep dive

Activity timeline11 mentions / 5d
01345Mentions · 2026-03-31: 3Mentions · 2026-04-01: 1Mentions · 2026-04-02: 5Mentions · 2026-04-08: 1Mentions · 2026-04-09: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-02: 4Technical Details · 2026-03-31: 3Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 5Technical Details · 2026-04-09: 103-3104-0104-0204-0804-09
Signal classification2 categories
Disclosure
763.6%
Patch
436.4%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-313
Disclosure2Patch1
2026-04-011
Disclosure1
2026-04-025
Disclosure2Patch3
2026-04-081
Disclosure1
2026-04-091
Disclosure1
Full discourse11 posts
  • InfoGuard Labs@InfoGuard_Labs
    Disclosure

    Another Security Agent, another Local Privilege Escalation! CVE-2026-3991: Symantec DLP Agent for Windows is affected by an LPE via a hardcoded OpenSSL configuration path. An easy way to get a SYSTEM shell directly into the DLP process. by @p0w1_ https://labs.infoguard.ch/advisories/cve-2026-3991_symantec-dlp-agent_local-privilege-escalation/

    Post summary

    The post announces CVE-2026-3991, a local privilege escalation in Symantec DLP Agent via a hardcoded OpenSSL path, noting that it allows a SYSTEM shell, but offers no PoC, exploit code, patch notice, or active exploitation details.

    016039212.7K
    295 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Symantec DLP Agent の脆弱性 CVE-2026-3991 が FIX:SYSTEM 権限奪取の可能性 https://iototsecnews.jp/2026/04/02/symantec-dlp-agent-flaw-exposed-systems-to-privilege-escalation-attacks/ 脆弱性 CVE-2026-3991 は、最終的な製品内に、開発時の古いファイルパスが残ってしまったことに起因します。本来は存在しないはずのパスを、プログラムが探しに行ってしまうという問題を突く攻撃者は、そこに偽のコンフィグ・ファイルを置くことで SYSTEM 権限の奪取が可能になります。”edpa.exe” という重要なプロセスが、外部のファイルを無条件に信じて読み込んでしまう設計上のミスが、深刻なリスクにつながっています。ご利用のチームは、ご注意ください。 #CVE20263991 #DataLossPreventionAgent #Symantec #Vulnerability

    Post summary

    The article discusses a recently fixed Symantec DLP Agent vulnerability (CVE‑2026‑3991) that permits privilege escalation via outdated file paths, urging teams to exercise caution.

    01000137
    483 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos Broadcom ❗ CVE-2026-3991 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-broadcom-2/ https://t.co/mXzWZpAFLe

    Post summary

    The post announces a new vulnerability (CVE-2026-3991) affecting Broadcom products and links to further information, but provides no technical, exploit, or mitigation details.

    00000124
    6.6K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Critical Symantec DLP Agent for Windows bug CVE-2026-3991 allows local privilege escalation to SYSTEM, CVSS 7.8, with Broadcom patches released March 30 2026. https://threatcluster.io/cluster/critical-symantec-dlp-agent-vulnerability-enables-privilege--62b5dc1a

    Post summary

    The announcement details a local privilege escalation vulnerability (CVE‑2026‑3991) in Symantec DLP Agent for Windows, includes its CVSS score, and notes that Broadcom released patches on March 30, 2026.

    0000062
    128 followersView on X
  • Israel@f1tym1
    Disclosure

    Symantec DLP Agent Vulnerability Let Attackers Escalate Privileges https://ift.tt/6ny2phO A high-severity security flaw has been identified in the Symantec Data Loss Prevention (DLP) Agent for Windows. Tracked as CVE-2026-3991, this vulnerability allows a low-privileged loca…

    Post summary

    The Symantec DLP Agent for Windows has a newly disclosed high‑severity privilege‑escalation flaw (CVE‑2026‑3991) that allows local low‑privileged users to gain higher rights; no PoC, exploit, or active exploitation has been reported.

    0000052
    948 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Local Privilege Esccalation in Symantec DLP Agent for Windows (CVE-2026-3991) 📅 **Timeline:** Disclosure: 2026-03-30; Patch: 2026-03-30 🆔 **CVE-2026-3991** | 📊 CVSS: 7.8 (HIGH 🟠) | 📈 EPSS: 2.04% 🛠️ **Exploit Maturity:** Publicly disclosed; patches available (2026-03-30) 📂 **Affected Versions:** Prior to 25.1 MP1, Prior to 16.1 MP2, Prior to 16.0 RU2 HF9, Prior to 16.0 RU1 MP1 HF12, Prior to 16.0 MP2 HF15 🔧 **Fixed Versions:** DLP 25.1 MP1, DLP 16.1 MP2, DLP 16.0 RU2 HF9, DLP 16.0 RU1 MP1 HF12, DLP 16.0 MP2 HF15 🫨 **Attack Vectors:** - Local authenticated user creates C:\VontuDev\ and supplies malicious openssl.cnf to trigger DLL side-load. - SYSTEM-run edpa.exe loads attacker-supplied DLL, enabling local privilege escalation. 📝 **Summary:** An authenticated local user can create a missing OpenSSL config path (C:\VontuDev\), drop a crafted openssl.cnf and rogue DLL, and cause the SYSTEM process edpa.exe to load it, yielding SYSTEM-level code execution. This enables persistent backdoors, EDR evasion, lateral movement and enterprise-wide data exfiltration — patch immediately. 📈 **Impact Scope:** SYSTEM-level code execution on affected endpoints; potential persistent backdoors, EDR/telemetry evasion, lateral movement and data exfiltration across enterprise networks. 🛡️ **Recommended Actions:** - Apply Broadcom official patches immediately (upgrade to listed fixed versions). - Inventory DLP agent versions and prioritize remediation for unpatched hosts. 🪢 **Related Resources:** - https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37306 - https://labs.infoguard.ch/advisories/cve-2026-3991_symantec-dlp-agent_local-privilege-escalation/ 🏷 **Tags:** #Cybersecurity #SymantecDLP #PrivilegeEscalation

    Post summary

    Symantec DLP Agent for Windows (CVE‑2026‑3991) suffers a local privilege escalation via a crafted OpenSSL config that triggers a DLL side‑load, enabling SYSTEM‑level execution; patches are available and should be applied immediately.

    0000046
    277 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Symantec Data Loss Prevention (DLP) Agent Local Privilege Escalation (CVE-2026-3991) 📅 **Timeline:** Disclosure: 2026-03-30 🆔 **CVE-2026-3991** | 📊 CVSS: 7.8 (HIGH 🟠) | 📈 EPSS: 2.038% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Prior to 25.1 MP1, Prior to 16.1 MP2, Prior to 16.0 RU2 HF9, Prior to 16.0 RU1 MP1 HF12, Prior to 16.0 MP2 HF15 🔧 **Fixed Versions:** 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, 16.0 MP2 HF15 🫨 **Attack Vectors:** - Local access required (AV:L) - Low attack complexity (AC:L) - Privileges required: Low (PR:L) - No user interaction (UI:N) 📝 **Summary:** CVE-2026-3991 is a local privilege escalation in Symantec DLP Agent for Windows that allows a low-privileged local user to gain elevated/system privileges and execute code with high impact to confidentiality, integrity, and availability. An attacker could access or exfiltrate DLP-protected data, install persistent malware, or disable security controls on affected endpoints. 📈 **Impact Scope:** Local low-privilege attacker can escalate to elevated/system privileges, execute code with elevated privileges, access or exfiltrate data protected by the DLP product, install persistent malware, or disable security controls on affected Windows endpoints. 🛡️ **Recommended Actions:** - Apply vendor updates to the fixed versions listed immediately. - Restrict local access and enforce least-privilege user rights on endpoints. - Monitor endpoints for suspicious process creation, privilege escalation activity, and DLP agent tampering. - Deploy or tune EDR/IDS detections and validate patches in staging before wide deployment. 🪢 **Related Resources:** - https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37306 - https://nvd.nist.gov/vuln/detail/CVE-2026-3991 🏷 **Tags:** #Cybersecurity #SymantecDLP #PrivilegeEscalation

    Post summary

    Symantec DLP Agent local privilege escalation CVE‑2026‑3991 is disclosed with high severity; patches are available and should be applied immediately to mitigate the risk.

    0000057
    277 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Symantec Data Loss Prevention (DLP) Agent Local Privilege Escalation (CVE-2026-3991) 📅 **Timeline:** Disclosure: 2026-03-30; Patch: Not Available 🆔 **CVE-2026-3991** | 📊 CVSS: 7.8 (High 🟠) | 📈 EPSS: 2.038% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Symantec DLP Windows Endpoint prior to 25.1 MP1, prior to 16.1 MP2, prior to 16.0 RU2 HF9, prior to 16.0 RU1 MP1 HF12, prior to 16.0 MP2 HF15 🔧 **Fixed Versions:** 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, 16.0 MP2 HF15 🫨 **Attack Vectors:** - Local (requires low privileges; no user interaction) 📝 **Summary:** A local privilege escalation in Symantec DLP Windows Endpoint (CVE-2026-3991) lets a low-privileged local user elevate to SYSTEM. Successful exploitation can disable security controls, expose sensitive data, install persistent backdoors, and enable lateral movement or full host compromise. 📈 **Impact Scope:** Local low-privilege user can escalate to SYSTEM on affected Windows endpoints — high impact on confidentiality, integrity, and availability; potential for persistent full-host compromise and lateral movement. 🛡️ **Recommended Actions:** - Apply vendor updates to affected agents (install 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, or 16.0 MP2 HF15 as applicable) - If immediate patching isn't possible, restrict local access and remove unnecessary local admin rights - Audit endpoints for signs of privilege escalation and anomalous service/config changes - Verify/enable EDR and monitor for suspicious process/service installations - Harden hosts, enforce least privilege, and rotate credentials/keys if compromise is suspected 🪢 **Related Resources:** - https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37306 - https://gbhackers.com/symantec-dlp-agent-flaw/ 🏷 **Tags:** #Cybersecurity #SymantecDLP #PrivilegeEscalation

    Post summary

    CVE-2026-3991 is a high‑severity local privilege escalation flaw in Symantec DLP agents with no patch yet but vendor updates and mitigation measures are detailed.

    0000060
    277 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    『may be susceptible to an Elevation of Privilege vulnerability,』 CVE-2026-3991 Symantec Data Loss Prevention Security Update https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37306

    Post summary

    Symantec Data Loss Prevention’s CVE‑2026‑3991, an elevation of privilege vulnerability, has a vendor‑provided security update available through Broadcom’s support site.

    00000358
    6.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3991 Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 MP2 HF15, may be susceptible to a Elevation of Pr… https://www.cve.org/CVERecord?id=CVE-2026-3991 ----- Traducción: CVE-2026-3991 Sym… http://infoflow.cloud`

    Post summary

    This post announces CVE-2026-3991 for Symantec Data Loss Prevention on Windows Endpoint prior to specific versions, indicating a potential elevation‐of‑privilege vulnerability.

    0000040
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3991 Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 MP2 HF15, may be susceptible to a Elevation of Pr… https://www.cve.org/CVERecord?id=CVE-2026-3991

    Post summary

    The post announces a privilege‑elevation vulnerability (CVE‑2026‑3991) affecting older Symantec Data Loss Prevention Windows Endpoint releases, with no mention of PoC, exploit code, or remediation.

    00000235
    56.9K followersView on X

Explore more