Description
Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privileged helper, which communicates with the application via XPC. The [ConsoleLogHelper copyConsoleIntoFileFromStartDate:] method executes a syslog command using attacker-controlled parameters without proper sanitization, enabling command injection. Successful exploitation allows a local attacker to execute arbitrary commands with root privileges through LaunchSynchronous.
Published: 2026-09-28
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Exam4 contains a local privilege escalation vulnerability in its com.extegrity.LogTool privileged helper. The helper communicates with the main application via XPC and runs a syslog command in the method copyConsoleIntoFileFromStartDate: without sanitizing attacker‑controlled parameters, allowing command injection. An attacker who can execute the helper locally can run arbitrary commands with root privileges through LaunchSynchronous, compromising system confidentiality, integrity, and availability.

Affected Systems

The affected product is Extegrity Exam4. No specific version information is provided in the advisory.

Risk and Exploitability

The vulnerability has a CVSS score of 7.8, indicating a high severity, while the EPSS score is not available and it is not listed in the CISA KEV catalog. It requires local access and is enabled by the privileged LogTool helper, so a local attacker who can trigger the XPC call can inject commands via syslog. The execution path requires the attacker to invoke the helper as root, which is granted by the helper’s launchd configuration, making exploitation straightforward for anyone with local account access.

Generated by OpenCVE AI on September 28, 2026 at 15:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Exam4 to the latest release that contains the fix for the command injection in LogTool.
  • If a patch is not yet available, limit the use of the com.extegrity.LogTool privileged helper by restricting XPC access to trusted users and, if possible, remove or disable the helper from launchd so it cannot run with elevated rights.
  • Apply least‑privilege best practices by ensuring local accounts that need to use Exam4 are not granted unnecessary administrative rights and monitor for unexpected syslog command execution.

Generated by OpenCVE AI on September 28, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 28 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Extegrity
Extegrity exam4
Vendors & Products Extegrity
Extegrity exam4

Mon, 28 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privileged helper, which communicates with the application via XPC. The [ConsoleLogHelper copyConsoleIntoFileFromStartDate:] method executes a syslog command using attacker-controlled parameters without proper sanitization, enabling command injection. Successful exploitation allows a local attacker to execute arbitrary commands with root privileges through LaunchSynchronous.
Title macOS Exam4 Local Privilege Escalation via Command Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Pentraze

Published:

Updated: 2026-09-28T16:22:26.038Z

Reserved: 2026-03-21T17:10:33.161Z

Link: CVE-2026-4556

cve-icon Vulnrichment

Updated: 2026-09-28T16:22:16.927Z

cve-icon NVD

Status : Received

Published: 2026-09-28T15:17:17.723

Modified: 2026-09-28T17:17:49.710

Link: CVE-2026-4556

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:22:01Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')