Privilege Escalation Vulnerability in Sophos Endpoint and Sophos Home for macOS
CVE-2026-18367

9.3CRITICAL

What is CVE-2026-18367?

A privilege escalation vulnerability in Sophos Endpoint for macOS and Sophos Home for macOS allows local users to gain elevated access by executing arbitrary code as root. This issue affects users running versions prior to 2026.1.1 for Sophos Endpoint and 10.11.6 for Sophos Home, posing significant risk if unaddressed.

Affected Version(s)

Sophos Endpoint for macOS MacOS 0 < 2026.1.1

Sophos Home for macOS MacOS 0 < 10.11.6

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hillel Pinto of XM Cyber
.