Insufficient Input Validation in ABR Affects Admin by Request Software
CVE-2026-78237
7.8HIGH
Key Information:
- Vendor
Admin By Request (abr)
- Status
- Vendor
- CVE Published:
- 26 August 2026
What is CVE-2026-78237?
The Admin by Request (ABR) software exhibits a security flaw due to insufficient input validation. This vulnerability allows a low-privileged user to execute an injection attack on the sudoers file, thereby gaining persistent root access to the system, even after the ABR session has terminated. This poses a significant risk of unauthorized control over system functions, potentially allowing malicious actors to conduct further attacks or gain sensitive information.
Affected Version(s)
Admin By Request (ABR) 5.2.2 and below
