Vulnerabilities in Privileged Access Management Application “Admin By Request”
26 August 2026
Two vulnerabilities have been discovered in the privileged access management application “Admin By Request” (ABR). The product owner has rolled out fixes for both reported vulnerabilities. Special thanks to the researchers and ABR for coordinating through CSA's Responsible Vulnerability Disclosure Policy.
Background
Admin By Request (ABR) is a privileged access management solution that enables organisations to manage and control elevated access on endpoints such as Windows and macOS workstations, as well as on laptops used across the enterprise.
CVE ID – Description
CVE-2026-78236| 8.8 (High) - An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.
CVE-2026-78237| 7.8 (High) – Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into the sudoers file, resulting in persistent root access that remained effective after the ABR session ended.
Affected Versions
Both vulnerabilities affect ABR macOS versions 5.2.2 and below.
Mitigation
ABR, the product owner, has rolled out fixes for both reported vulnerabilities. Users and administrators of affected product versions are advised to update to the latest version promptly.
Timeline
2026-04-28 – Vendor Disclosure
2026- 06-22 – Vendor Patched
2026- 08-25 – Public Release
Credit
Discovered by:
Kang Hao Leng, Timothy Lee, Wen Bin Kong from Innoedge Labs
Tan Inn Fung, Sean Seah, Cameron Leong from GovTech Cybersecurity Group (CSG)
Ronald Chia, Manzel Seet from Assurity Trusted Solutions
References
https://docs.adminbyrequest.com/security-advisories/abr-mac-26-01.htm
https://docs.adminbyrequest.com/security-advisories/abr-mac-26-02.htm
