Junglewise Threat Intelligence

CVE-2026-10610: ESET security applications for macOS privilege escalation in Uninstaller

CVE-2026-10610 · Severity: info · CVSS 8.5 · Published 2026-07-24

Vendors: Eset.

Executive brief

A security vulnerability in ESET antivirus software for macOS could allow a person with limited access to a computer to gain full administrative control. By creating specially named folders, an attacker can trick a background maintenance tool into running unauthorized commands with the highest system privileges. This could lead to the complete takeover of the affected Mac, allowing for the theft of sensitive data or the disabling of security protections.

Technical details

A local privilege escalation vulnerability exists in ESET Endpoint Security and ESET Cyber Security for macOS due to improper privilege management (CWE-269). A helper binary within the ESET Uninstaller application bundle runs with root permissions and fails to properly sanitize directory names containing shell metacharacters. An unprivileged local attacker can exploit this by creating a specially crafted directory name that triggers arbitrary command injection when parsed by the helper tool. Successful exploitation allows the attacker to execute arbitrary code as the root user. ESET has released patches across multiple version branches to address this flaw.

Affected products

  • ESET ESET Endpoint Security for macOS 8.0.7200.0 and earlier, 8.1.200.0 and earlier, 9.0.5400.0 and earlier, 9.1.2500.0 and earlier
  • ESET ESET Cyber Security for macOS 9.0.5300.0 and earlier

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: patched
  • 2026-07-24: advisory

References

Related threats