CVE-2026-78236
8.8Admin By Request · Admin By Request (ABR)
An insecure PIN derivation mechanism in Admin By Request allows a low-privileged user to escalate privileges to administrator by masquerading as an Apple-signed process via XPC.
Executive summary
A high severity privilege escalation vulnerability in Admin By Request allows local users to gain administrative rights by abusing the PIN derivation process.
Vulnerability
This vulnerability stems from an insecure PIN derivation mechanism that allows a low-privileged local user to manipulate Cross-Process Communication (XPC). By masquerading as a trusted Apple-signed process, the attacker can successfully escalate to administrative privileges.
Business impact
The CVSS score of 8.8 highlights the critical nature of this privilege escalation flaw. An attacker who has already gained low-privileged access to a system can leverage this vulnerability to assume full administrative control, leading to complete system compromise and potential lateral movement across the network.
Remediation
Immediate Action: Update the Admin By Request application to the latest version provided by the vendor to remediate the PIN derivation flaw.
Proactive Monitoring: Monitor system logs for unauthorized attempts to initiate XPC communications or unexpected privilege escalation events.
Compensating Controls: Restrict local user account permissions and enforce strict application control policies to limit the scope of potential local attacks.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations using Admin By Request must treat this vulnerability with high urgency. Patching the software is the only definitive way to close the privilege escalation vector, and administrators should ensure all managed devices are updated immediately.