Privilege Escalation Vulnerability in ABR by Admin By Request
CVE-2026-78236
8.8HIGH
Key Information:
- Vendor
Admin By Request (abr)
- Status
- Vendor
- CVE Published:
- 26 August 2026
What is CVE-2026-78236?
The ABR product by Admin By Request contains an insecure PIN derivation mechanism that can be exploited by low-privileged users. By leveraging Cross-Process Communication (XPC), an attacker can impersonate an Apple-signed process to gain elevated privileges, potentially allowing unauthorized administrative access.
Affected Version(s)
Admin By Request (ABR) 5.2.2 and below
