Impact
Path traversal in macOS's handling of directory server a network directory server to manipulate file paths, potentially executing arbitrary code with root privileges. Based on the description, it is inferred that such manipulation might also permit the attacker to read or write files outside the intended directory, relating to the classic path traversal weakness. The vulnerability was addressed by adding stricter path validation, but lacking this fix may enable unintended file system access and code execution.
Affected Systems
macOS systems, specifically the macOS Golden Gate, macOS Sequoia, and macOS Tahoe releases. The vulnerability is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Older versions below these are affected.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of < 1 % indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker must have administrative or similar control over a network‑bound directory service to exploit the flaw; once accessed, they can elevate privileges to root and run arbitrary code on the target host.
OpenCVE Enrichment