Executive brief
Admin By Request is a privileged access management solution that controls elevated access on enterprise workstations. A flaw in how the application derives PINs allows a local user with standard privileges to impersonate an Apple-signed process and trick the ABR service into granting administrator access without authorization. This bypasses the intended approval workflow and gives attackers persistent elevated control over the affected system.
Technical details
The vulnerability stems from an insecure PIN derivation mechanism in the Admin By Request macOS client. An attacker with local (non-root) access can exploit this by masquerading as an Apple-signed process to communicate with the ABR service via XPC (Cross-Process Communication), allowing them to request and obtain non-approved privilege escalation to administrator level. The attack requires only local code execution capability and no user interaction. The vulnerability was patched in ABR 5.3 for macOS; all versions 5.2.2 and below are affected.
Affected products
- Admin By Request Admin By Request 5.2.2 and below
Timeline
- 2026-04-28: disclosed
- 2026-06-22: patched
- 2026-08-26: advisory