---
id: CVE-2026-15379
title: >-
  The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any
  local standard user to read the contents of any file accessible to the SYSTEM
  account, bypassing filesystem ACLs
summary: >-
  The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any
  local standard user to read the contents of any file accessible to the SYSTEM
  account, bypassing filesystem ACLs. No admin privileges required. The provider
  r…
severity: none
published: '2026-07-17'
updated: '2026-07-19'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15379'
references:
  - url: >-
      https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37995
    label: secure@symantec.com
tags:
  - nvd
epss: 0.00146
epssPercentile: 0.03205
ingestedAt: '2026-07-19T14:31:06.053Z'
---

## Overview

The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypassing filesystem ACLs. No admin privileges required. The provider reverts to the LocalSystem context when servicing WMI queries without re-impersonating the caller. Any local standard user can therefore read SYSTEM-readable files — including configuration files, service logs, and secrets stored with SYSTEM/Administrator-only ACLs — by querying the provider directly.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
