Description
An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.
Published: 2026-08-26
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation to Administrator
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from an insecure PIN derivation mechanism in Admin By Request (ABR). A low-privileged user can construct a PIN that matches the expected value, enabling the application to authenticate the attacker as if it were a legitimate Apple-signed process. This authentication bypass leads to privilege escalation, allowing the attacker to gain full administrator rights. The weakness is a classic authorization flaw, cited by CWEs 284, 285, 287, and 327.

Affected Systems

This flaw affects the Admin By Request (ABR) suite. While the precise affected releases are not enumerated in the advisory, all versions lacking the vendor’s latest patch are potentially vulnerable. Users should check the revision history on the vendor’s site and update immediately if an unpatched release is in use.

Risk and Exploitability

With a CVSS score of 8.8, the vulnerability is considered high severity, yet the EPSS score of less than 1% indicates that exploitation is currently unlikely. It is not listed in the CISA KEV catalog. The attack requires local access to send crafted Cross-Process Communication messages that impersonate an Apple‑signed process; thus an attacker must be able to execute code on the target machine to leverage the flaw.

Generated by OpenCVE AI on August 26, 2026 at 18:07 UTC.

Remediation

Vendor Solution

Users and administrators of affected product versions are advised to update to the latest version promptly.


OpenCVE Recommended Actions

  • Update Admin By Request (ABR) to the latest vendor release as soon as it becomes available.
  • Where possible, restrict XPC traffic to only those processes that are properly signed by Apple, thereby preventing unauthorized process impersonation.
  • Enable auditing and monitor system logs for anomalous XPC traffic directed to ABR, and investigate any suspicious events promptly.

Generated by OpenCVE AI on August 26, 2026 at 18:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Admin By Request (abr)
Admin By Request (abr) admin By Request (abr)
Vendors & Products Admin By Request (abr)
Admin By Request (abr) admin By Request (abr)

Wed, 26 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-287
CWE-327
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 26 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Description An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.
Title Insecure PIN derivation mechanism in Admin By Request (ABR)
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Admin By Request (abr) Admin By Request (abr)
cve-icon MITRE

Status: PUBLISHED

Assigner: CSA

Published:

Updated: 2026-08-28T06:41:41.298Z

Reserved: 2026-08-24T03:00:17.827Z

Link: CVE-2026-78236

cve-icon Vulnrichment

Updated: 2026-08-26T14:02:05.329Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T08:16:46.600

Modified: 2026-09-03T16:59:26.287

Link: CVE-2026-78236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:33:44Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-285

    Improper Authorization

  • CWE-287

    Improper Authentication

  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm