Skip to content
Agent 4 7 5 5374

Agent 4 7 5 5374

www.iru.com • June 24, 2026

CVE-2026-39118 — An access control issue existed in the Kandji Agent (macOS). A local attacker with standard user privileges could invoke restricted functionality. This issue was addressed with improved validation.

Affected: Kandji Agent (macOS) before 4.7.5 (5374)

Fixed in: 4.7.5 (5374), available March 25, 2026 (this version)

Severity: CVSS 3.1 — 6.1 (Medium) · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

Credit: Iru thanks Hillel Pinto of XM Cyber for reporting this issue.

Extracted Entities

Platforms (1)