Admin By Request (ABR) - Insecure PIN derivation mechanism

CVE ID

CVE-2026-78236

Description

An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.

Tested Versions

5.2.2

Details

Admin By Request (ABR) is a privileged access management solution that enables organisations to manage and control elevated access on endpoints such as Windows and macOS workstations, as well as on laptops used across the enterprise.

Timeline

  • 2026-04-28 - Vendor Disclosure
  • 2026-06-22 - Vendor Patched
  • 2026-08-25 - Public Release

Credit

Discovered by GovTech Cybersecurity Group.