Admin By Request (ABR) - Insufficient input validation

CVE ID

CVE-2026-78237

Description

Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into the sudoers file, resulting in persistent root access that remained effective after the ABR session ended.

Tested Versions

5.2.2

Details

Admin By Request (ABR) is a privileged access management solution that enables organisations to manage and control elevated access on endpoints such as Windows and macOS workstations, as well as on laptops used across the enterprise.

Timeline

  • 2026-04-28 - Vendor Disclosure
  • 2026-06-22 - Vendor Patched
  • 2026-08-25 - Public Release

Credit

Discovered by GovTech Cybersecurity Group.