CVE-2026-18367

Summary

A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.

Affected Software

VendorProductVersion RangeStatus
SophosSophos Endpoint for macOS0 < 2026.1.1affected
SophosSophos Home for macOS0 < 10.11.6affected

Weaknesses

  • CWE-285: CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

References