CVE-2026-18367
Severity CVSS v4.0:
Pending analysis
Type:
CWE-285
Improper Authorization
Publication date:
06/08/2026
Last modified:
07/08/2026
Description
A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
Impact
Base Score 3.x
9.30
Severity 3.x
CRITICAL


