Junglewise Threat Intelligence

CVE-2026-78237: Admin By Request macOS sudoers injection privilege escalation

CVE-2026-78237 · Severity: high · CVSS 7.8 · Published 2026-08-26

Executive brief

Admin By Request is a privileged access management solution that controls elevated access on enterprise workstations and laptops. A vulnerability in the macOS client allows a low-privileged user to inject malicious entries into the system's sudoers configuration file, granting themselves persistent root access that survives after the management session ends. This bypasses the intended security controls and gives an attacker permanent administrative control over the affected computer.

Technical details

This vulnerability is an input validation flaw in Admin By Request macOS client versions 5.2.2 and below. The vulnerability allows a low-privileged user to inject arbitrary entries into the sudoers file, resulting in unauthorized privilege escalation to root. Exploitation requires local access to the endpoint and the ability to programmatically execute the exploit; notably, the attack leverages a related XPC vulnerability (CVE-2026-78236, detailed in ABR-MAC-26-01) to facilitate the injection. Once exploited, an attacker gains non-approved persistent root access that remains effective even after the ABR session terminates. The fix is available in Admin By Request version 5.3 for macOS and later.

Affected products

  • Admin By Request Admin By Request 5.2.2 and below

Timeline

  • 2026-04-28: disclosed
  • 2026-06-22: patched
  • 2026-08-26: advisory

References

Related threats