Impact
The vulnerability is a local privilege escalation that permits a user on a macOS system to execute arbitrary code with root privileges through Sophos Endpoint for macOS or Sophos Home for macOS. By exploiting an improper authorization enforcement flaw (CWE‑285), an attacker can gain complete control over the affected machine, reading, modifying, or deleting any data, installing software, and tampering with system settings. The flaw exists only in versions older than 2026.1.1 for Endpoint and 10.11.6 for Home.
Affected Systems
Affected systems are macOS computers running Sophos Endpoint for macOS prior to version 2026.1.1 or Sophos Home for macOS prior to version 10.11.6. The vulnerability applies to any user with local access, regardless of their existing privilege level, because the flaw can be triggered by local user actions.
Risk and Exploitability
The CVSS score of 9.3 signals a high severity and the lack of a network access requirement means an attacker only needs local login to exploit the flaw. EPSS is not available, but the ease of local exploitation and the destructive consequences create a significant risk. The vulnerability has not yet been listed in the CISA KEV catalog, but the impact and local exploitation pathway warrant swift remediation.
OpenCVE Enrichment