CVE-2026-18367
9.3
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Summary
A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Sophos | Sophos Endpoint for macOS | 0 < 2026.1.1 | affected |
| Sophos | Sophos Home for macOS | 0 < 10.11.6 | affected |
Weaknesses
- CWE-285: CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.