PatchSiren

Admin By Request (ABR) CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Admin By Request (ABR) CVE published 2026-08-26

CVE-2026-78237

The CVE-2026-78237 vulnerability, caused by insufficient input validation in Adminbyrequest (ABR), allows a low-privileged user to inject malicious entries into the sudoers file, resulting in persistent root access that remains effective after the ABR session ends. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. System administrators and security teams using Adminbyrequest s [truncated]

HIGH Admin By Request (ABR) CVE published 2026-08-26

CVE-2026-78236

The CVE-2026-78236 record describes an insecure PIN derivation mechanism in ABR that allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process. This vulnerability affects organizations using the impacted product, particularly those with low-privileged users. Administrators and security teams sh [truncated]