Description
Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user.
Published: 2026-07-24
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in macOS versions of ESET Cyber Security and ESET Endpoint Security permits an attacker who can execute code locally to create or overwrite an arbitrary file with content fully under their control. The CVE description does not state the consequences of executing that file; based on common risk scenarios, it is inferred that such a file could be used to compromise system integrity or achieve code execution, but this is not explicitly documented in the advisory.

Affected Systems

ESET Cyber Security for macOS and ESET Endpoint Security for macOS are affected. Specific vulnerable releases are not listed, so all currently deployed versions should be considered at risk until ESET issues a patch.

Risk and Exploitability

The CVSS score of 8.5 reflects a high severity flaw, while the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local access, meaning the threat is limited to users who already have some privilege on the machine. Based on the description, it is inferred that the attacker must be physically present or able to run code on the same machine to exploit the flaw. Even with the low exploitation probability, the high severity warrants rapid remediation.

Generated by OpenCVE AI on August 4, 2026 at 15:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update ESET Cyber Security for macOS and ESET Endpoint Security for macOS to the latest release that contains the privileged file‑write fix.
  • If a patch is not yet available, delay use of privileged functions or disable unnecessary elevated features until the vendor releases a fix.
  • As a short‑term countermeasure, restrict write permissions on directories used by these applications for privileged files to mitigate potential misuse until a patch is applied.

Generated by OpenCVE AI on August 4, 2026 at 15:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Eset
Eset cyber Security
Eset endpoint Security
Vendors & Products Eset
Eset cyber Security
Eset endpoint Security

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user.
Title Local privilege escalation in ESET security applications for macOS
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Eset Cyber Security Endpoint Security
cve-icon MITRE

Status: PUBLISHED

Assigner: ESET

Published:

Updated: 2026-07-24T10:49:13.322Z

Reserved: 2026-04-30T06:28:55.139Z

Link: CVE-2026-7483

cve-icon Vulnrichment

Updated: 2026-07-24T10:49:07.083Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T10:16:32.637

Modified: 2026-07-30T19:14:09.213

Link: CVE-2026-7483

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:15:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management