What is CVE-2026-18367?
This is a critical privilege escalation vulnerability in Sophos Endpoint and Sophos Home for macOS that allows local users to execute arbitrary code with root privileges. Successful exploitation could grant a low-privileged user full control over the affected system. Users must urgently upgrade Sophos Endpoint to version 2026.1.1 or later, and Sophos Home to version 10.11.6 or later to remediate the issue.
Azərbaycanca: Bu, macOS üçün Sophos Endpoint və Sophos Home proqramlarında yerli istifadəçilərə root hüquqları ilə ixtiyari kod icra etməyə imkan verən ciddi imtiyaz yüksəltmə (privilege escalation) zəifliyidir. Bu təhlükəsizlik boşluğu uğurla istismar olunarsa, məhdud hüquqlu istifadəçi sistem üzərində tam nəzarət əldə edə bilər. Problemi aradan qaldırmaq üçün Sophos Endpoint-i 2026.1.1, Sophos Home-u isə 10.11.6 versiyasına və ya daha yenisinə təcili yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
What can an attacker gain by successfully exploiting CVE-2026-18367?
This vulnerability allows a local user with limited privileges to execute arbitrary code with root privileges, potentially giving the attacker full control over the affected system.
To which version must Sophos Home be upgraded to fix CVE-2026-18367?
Sophos Home users must urgently upgrade to version 10.11.6 or later to remediate the vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.