Executive brief
Omnissa Workspace ONE Assist for macOS, a tool used by IT departments to remotely troubleshoot and support employee computers, contains a security flaw that allows a local user to gain elevated permissions. An attacker who already has basic access to a Mac could exploit this vulnerability to take full control of the system, potentially accessing sensitive data or bypassing security controls. This poses a significant risk to corporate device integrity and data confidentiality.
Technical details
Omnissa Workspace ONE Assist for macOS is vulnerable to local privilege escalation (LPE) due to improper limitation of a pathname to a restricted directory, commonly known as path traversal (CWE-22). An attacker with local access and low-level privileges can exploit this flaw to manipulate file paths and execute operations with the higher privileges of the Assist application. Successful exploitation results in a complete compromise of confidentiality, integrity, and availability (CVSS 7.8). The vulnerability is tracked as CVE-2026-22926 and users are advised to consult Omnissa advisory OMSA-2026-0001 for patching information.
Affected products
- Omnissa Workspace ONE Assist macOS versions prior to fixed release
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory