Privilege Escalation Vulnerability in ABR by Admin By Request
CVE-2026-78236

8.8HIGH

What is CVE-2026-78236?

The ABR product by Admin By Request contains an insecure PIN derivation mechanism that can be exploited by low-privileged users. By leveraging Cross-Process Communication (XPC), an attacker can impersonate an Apple-signed process to gain elevated privileges, potentially allowing unauthorized administrative access.

Affected Version(s)

Admin By Request (ABR) 5.2.2 and below

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.