CVE-2026-39118
CVSS 8.4 HIGH: an issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client… EPSS 0.2% (5º percentile).
Vulnerabilità · 96 giorni fa
Su macOS il problema non è solo l’escalation di privilegi. Un utente con diritti standard può far passare per affidabile un componente falso e usare i servizi XPC privilegiati per disattivare i controlli che dovrebbero vederlo, creando un buco di telemetria senza admin rights né exploit del kernel.
XM Cyber ha dimostrato il comportamento su CrowdStrike Falcon e Kandji, e lo collega a CVE-2026-39118. Il punto è più ampio dei due prodotti: ogni ambiente che si affida a helper XPC privilegiati può ritrovarsi con EDR e MDM muti dopo un foothold a livello utente, proprio dove ci si aspetta ancora visibilità.
CVSS 8.4 HIGH: an issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client… EPSS 0.2% (5º percentile).
3 fonti che coprono questa storia
macOS Flaw Lets Standard Users Disable EDR and MDM
macos-xpc-flaw-disable-edr-mdm-standard-user-xm-cyber
macOS Weaknesses Chained to Silently Disable Endpoint Security Agents
A standard non-admin account is sufficient to conduct an attack that exploits legitimate OS behavior rather than software vulnerabilities.
Apple's MacOS Gap Lets Users Disable Security Tools
Attackers can exploit the issue to disable security and integrated browser tools without needing administrator privileges or kernel exploits.
Part of the PlainSec briefing for 2026-06-26