CVE-2026-3991: Elevation of Privileges in Symantec Data Loss Prevention Windows Endpoint
Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 MP2 HF15, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3991?
CVE-2026-3991 has a high severity rating due to its potential for privilege escalation.
How do I fix CVE-2026-3991?
To fix CVE-2026-3991, upgrade to a version of Symantec Data Loss Prevention Windows Endpoint that is 25.1 MP1 or later, or 16.1 MP2 or later.
What versions are affected by CVE-2026-3991?
CVE-2026-3991 affects versions of Symantec Data Loss Prevention Windows Endpoint prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 MP2 HF15.
What does CVE-2026-3991 exploit?
CVE-2026-3991 exploits a vulnerability that allows for elevation of privileges within the affected software.
Is there a workaround for CVE-2026-3991?
There are no known workarounds for CVE-2026-3991; the recommended action is to update the software.