CVE-2026-78237

Summary

Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into the sudoers file, resulting in persistent root access that remained effective after the ABR session ended.

Affected Software

VendorProductVersion RangeStatus
Admin By Request (ABR)Admin By Request (ABR)5.2.2 and belowaffected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References