Description
Waves Central for macOS contains a local privilege escalation in the privileged helper service. The helper authorizes connecting XPC clients by comparing the caller's code-signing certificate chain for equality with its own, rather than validating the caller against a pinned code requirement (application identifier and Team ID). A local, authenticated user can execute code within the vendor-signed process, satisfy the helper's client check, and cause the helper to execute a script with root privileges. Fixed in 17.0.
Published: 2026-09-08
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the Waves Central privileged helper service on macOS, which authenticates XPC clients by comparing the caller's code‑signing certificate chain to its own instead of validating against a pinned requirement. A local authenticated user can supply a process signed by the same team ID, pass the helper’s check, and cause the helper to execute a script with root privileges. This flaw allows the attacker to gain root access, enabling full system compromise.

Affected Systems

Vulnerable versions of Waves Central for macOS prior to 17.0, distributed by Waves Audio Ltd. The issue affects the helper component used by the application on all macOS releases before 17.0.

Risk and Exploitability

With a CVSS score of 8.4 the severity is high, though the EPSS score is not available and it is not listed in the CISA KEV catalog. The attack requires local authenticated access, so an insider or an attacker who has logged into the system can exploit it immediately. The high score reflects the ability to obtain root privileges and the potential for widespread impact.

Generated by OpenCVE AI on September 9, 2026 at 09:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Waves Central version 17.0 or later to apply the fix for the helper service authentication check.
  • If upgrading is delayed, restrict local users from launching the Waves Central privileged helper by removing them from administrative roles or disabling the helper via launchctl until the patch is applied.
  • Enable Gatekeeper and macOS notarization enforcement so only trusted, notarized applications can run, reducing the chance of executing malicious scripts via the helper.

Generated by OpenCVE AI on September 9, 2026 at 09:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Waves Audio
Waves Audio waves Central
Vendors & Products Waves Audio
Waves Audio waves Central

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Waves Central for macOS contains a local privilege escalation in the privileged helper service. The helper authorizes connecting XPC clients by comparing the caller's code-signing certificate chain for equality with its own, rather than validating the caller against a pinned code requirement (application identifier and Team ID). A local, authenticated user can execute code within the vendor-signed process, satisfy the helper's client check, and cause the helper to execute a script with root privileges. Fixed in 17.0.
Title Waves Central local privilege escalation via Improper XPC Client Authentication in macOS
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Waves Audio Waves Central
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-09-14T13:50:49.320Z

Reserved: 2026-09-08T14:09:48.155Z

Link: CVE-2026-86819

cve-icon Vulnrichment

Updated: 2026-09-14T13:47:56.185Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T21:18:47.520

Modified: 2026-09-14T14:17:17.173

Link: CVE-2026-86819

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T05:00:12Z

Weaknesses