CVE-2026-39118Disclosure

MEDIUMCVSS 8.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke restricted agent functionality.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-06-29); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-06-25: 1Mentions · 2026-06-29: 2Mentions · 2026-07-04: 1Mentions · 2026-07-18: 1PoC Mentioned / Linked · 2026-06-29: 1Exploit Tool / Code · 2026-06-29: 1Patch / Workaround · 2026-07-04: 1Technical Details · 2026-06-25: 1Technical Details · 2026-06-29: 2Technical Details · 2026-07-04: 1Technical Details · 2026-07-18: 106-2506-2907-0407-18
Signal classification3 categories
Disclosure
360.0%
PoC
120.0%
General
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-06-251
Disclosure1
2026-06-292
Disclosure1PoC1
2026-07-041
Disclosure1
2026-07-181
General1
Full discourse5 posts
  • كاسبر سكاي@KasperskyDev
    Disclosure

    ⚠️ ثغرة في ماك أو إس تتيح لأي مستخدم عادي تعطيل وكلاء الحماية دون صلاحيات إدارية. المعرّف : CVE-2026-39118 المكتشف : XM Cyber المتأثر : Kandji MDM < 4.7.5 الحل : Upgrade Kandji agent #CVE #macOS #EDR #CyberSecurity

    Post summary

    MacOS vulnerability CVE‑2026‑39118 enables regular users to disable protection agents; Kandji MDM (<4.7.5) users should immediately upgrade the agent.

    01000128
    40.0K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    macOS の XPC 通信基盤に脆弱性-一般ユーザー権限で CrowdStrike・Kandji のセキュリティ機能を無効化(CVE-2026-39118) https://rocket-boys.co.jp/security-measures-lab/macos-xpc-vulnerability-cve-2026-39118/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The article announces CVE-2026-39118, a macOS XPC communication vulnerability that allows local users to disable security features of CrowdStrike and Kandji, without providing a PoC or evidence of exploitation.

    01000144
    445 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    XM Cyber researchers disclosed CVE-2026-39118, a macOS vulnerability allowing standard users to circumvent privilege controls and interfere with security products like CrowdStrike Falcon and Kandji MDM, Kandji confirmed. https://t.co/U4UsUiKwja

    Post summary

    XM Cyber researchers have disclosed CVE‑2026‑39118, a macOS privilege‑escalation vulnerability that allows standard users to bypass privilege controls and compromise security solutions such as CrowdStrike Falcon and Kandji MDM.

    10000140
    395 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-39118: Kandji Agent Privilege Escalation Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04pYRQf0

    Post summary

    The snippet only provides a title and a link, offering minimal explicit information about the vulnerability beyond its type, so no definitive classification can be asserted.

    0000051
    32 followersView on X
  • Cyberdark Impact@kenebeii
    PoC

    🔐 セキュリティトレンド (15:31 JST) ① ロシアのハッカー、Signalのバックアップ復元キーを標的に:FBIが警告 - Codebook https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/46375/ ② 一般ユーザー権限で CrowdStrike・Kandji のセキュリティ機能を無効化(CVE-2026-39118) https://rocket-boys.co.jp/security-measures-lab/macos-xpc-vulnerability-cve-2026-39118/ ③ 「libssh2」に整数オーバーフローの脆弱性 - 実証コードも公開 - Security NEXT https://www.security-next.com/186519 ④ AIブームは暗号資産の逆風か?資金流出の先に見える「自動決済」の新需要 - マネクリ https://media.monex.co.jp/articles/amp/29646 ⑤ LLMのOpenAI、次世代フラッグシップモデルGPT-5.6シリーズを発表し - AT PARTNERS https://www.atpartners.co.jp/news/2026-06-29-openai-the-llm-developer-has-announced-its-next-generation-flagship-gpt-5-6-series-and-the-head-of-apple-vision-pro-has-joined-the-company-to-accelerate-hardware-development #セキュリティ #CyberSecurity

    Post summary

    The post announces a CVE-2026-39118 Mac XPC vulnerability and shares a proof‑of‑concept for an integer overflow in libssh2, but does not report active exploitation or patches.

    00000151
    826 followersView on X

Explore more