Description
A path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker with control of a network directory server may be able to execute arbitrary code with root privileges.
Published: 2026-09-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via Path Traversal
Action: Immediate Patch
AI Analysis

Impact

Path traversal in macOS's handling of directory server a network directory server to manipulate file paths, potentially executing arbitrary code with root privileges. Based on the description, it is inferred that such manipulation might also permit the attacker to read or write files outside the intended directory, relating to the classic path traversal weakness. The vulnerability was addressed by adding stricter path validation, but lacking this fix may enable unintended file system access and code execution.

Affected Systems

macOS systems, specifically the macOS Golden Gate, macOS Sequoia, and macOS Tahoe releases. The vulnerability is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Older versions below these are affected.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. The EPSS score of < 1 % indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker must have administrative or similar control over a network‑bound directory service to exploit the flaw; once accessed, they can elevate privileges to root and run arbitrary code on the target host.

Generated by OpenCVE AI on September 20, 2026 at 19:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest macOS update that includes the path-validation fix (macOS Golden Gate 27, Sequoia 15.8, or TahoeIf an update is not yet available, restrict access to the directory service by limiting guest or external connections and enforce strict ACLs on shared directories to prevent malicious path traversal.
  • Monitor system logs for signs of directory traversal attempts and enforce audit policies to alert on invalid path access patterns.
  • Restrict network access to the directory service by implementing firewall rules that block untrusted hosts and ensure that only authorized machines can contact the service.

Generated by OpenCVE AI on September 20, 2026 at 19:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title macOS Path Traversal Enabling Arbitrary Code Execution via Network Directory Server

Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Tue, 15 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title macOS Path Traversal Enabling Arbitrary Code Execution via Network Directory Server

Tue, 15 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker with control of a network directory server may be able to execute arbitrary code with root privileges.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T03:56:25.110Z

Reserved: 2026-09-01T21:13:17.754Z

Link: CVE-2026-84568

cve-icon Vulnrichment

Updated: 2026-09-14T22:30:31.709Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:33.000

Modified: 2026-09-15T17:38:44.540

Link: CVE-2026-84568

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:00:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')