Description
A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
Published: 2026-08-06
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a local privilege escalation that permits a user on a macOS system to execute arbitrary code with root privileges through Sophos Endpoint for macOS or Sophos Home for macOS. By exploiting an improper authorization enforcement flaw (CWE‑285), an attacker can gain complete control over the affected machine, reading, modifying, or deleting any data, installing software, and tampering with system settings. The flaw exists only in versions older than 2026.1.1 for Endpoint and 10.11.6 for Home.

Affected Systems

Affected systems are macOS computers running Sophos Endpoint for macOS prior to version 2026.1.1 or Sophos Home for macOS prior to version 10.11.6. The vulnerability applies to any user with local access, regardless of their existing privilege level, because the flaw can be triggered by local user actions.

Risk and Exploitability

The CVSS score of 9.3 signals a high severity and the lack of a network access requirement means an attacker only needs local login to exploit the flaw. EPSS is not available, but the ease of local exploitation and the destructive consequences create a significant risk. The vulnerability has not yet been listed in the CISA KEV catalog, but the impact and local exploitation pathway warrant swift remediation.

Generated by OpenCVE AI on August 7, 2026 at 00:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Sophos Endpoint for macOS to version 2026.1.1 or newer.
  • Upgrade Sophos Home for macOS to version 10.11.6 or newer.
  • Apply local account restrictions and enforce least privilege to limit user elevation capabilities.

Generated by OpenCVE AI on August 7, 2026 at 00:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Sophos Endpoint and Home for macOS Allows Arbitrary Code Execution as Root

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
First Time appeared Sophos
Sophos sophos Endpoint For Macos
Sophos sophos Home For Macos
Weaknesses CWE-285
CPEs cpe:2.3:a:sophos:sophos_endpoint_for_macos:*:*:macos:*:*:*:*:*
cpe:2.3:a:sophos:sophos_home_for_macos:*:*:macos:*:*:*:*:*
Vendors & Products Sophos
Sophos sophos Endpoint For Macos
Sophos sophos Home For Macos
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Sophos Sophos Endpoint For Macos Sophos Home For Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: Sophos

Published:

Updated: 2026-08-07T13:29:58.749Z

Reserved: 2026-07-30T09:43:38.584Z

Link: CVE-2026-18367

cve-icon Vulnrichment

Updated: 2026-08-07T13:29:55.309Z

cve-icon NVD

Status : Received

Published: 2026-08-06T22:16:50.010

Modified: 2026-08-07T14:16:57.447

Link: CVE-2026-18367

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:00:05Z

Weaknesses