CVE-2026-18367
Endpoint: Improper Authorization (CVE-2026-18367)
criticalEPSS 0.2%
Affected
- Sophos/Endpoint
2026.1.1..* - Sophos/Endpoint
Home 10.11.6..*
Description
A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
SophosEndpoint
2026.1.1Home 10.11.6Metrics
Show all metrics
Severity
critical
71.29
no public PoC known
9.3
Published
2026-08-06 20:30 UTC
CWE-285
Weakness classes (CWE)
CWE-285Class
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- New CVE Received2026-08-06 22:16 UTC· security-alert@sophos.com
- Affected: Sophos Endpoint for macOS, Sophos Home for macOS
- Description: A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
- CVSS V3.1: AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- CWE: CWE-285