CVE-2026-39118 — An access control issue existed in the Kandji Agent (macOS). A local attacker with standard user privileges could invoke restricted functionality. This issue was addressed with improved validation.
Affected: Kandji Agent (macOS) before 4.7.5 (5374)
Fixed in: 4.7.5 (5374), available March 25, 2026 (this version)
Severity: CVSS 3.1 — 6.1 (Medium) · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Credit: Iru thanks Hillel Pinto of XM Cyber for reporting this issue.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
