CVE-2026-78236
Admin By Request (ABR) - Insecure PIN derivation mechanism
CVE ID
CVE-2026-78236
Description
An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.
Tested Versions
5.2.2
Details
Admin By Request (ABR) is a privileged access management solution that enables organisations to manage and control elevated access on endpoints such as Windows and macOS workstations, as well as on laptops used across the enterprise.
Timeline
- 2026-04-28 - Vendor Disclosure
- 2026-06-22 - Vendor Patched
- 2026-08-25 - Public Release
Credit
Discovered by GovTech Cybersecurity Group.