CVE-2026-18367

Endpoint: Improper Authorization (CVE-2026-18367)

criticalEPSS 0.2%

Affected

  • Sophos/Endpoint 2026.1.1..*
  • Sophos/Endpoint Home 10.11.6..*

Description

A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

SophosEndpoint
2026.1.1Home 10.11.6

Metrics

9.3
Source: cna-v3
6.7 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
critical
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-06 20:30 UTC
CWE-285

Weakness classes (CWE)

  • CWE-285Class

    Improper Authorization

    The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. New CVE Received2026-08-06 22:16 UTC· security-alert@sophos.com
    • Affected: Sophos Endpoint for macOS, Sophos Home for macOS
    • Description: A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
    • CVSS V3.1: AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    • CWE: CWE-285

Linked advisories