CVE-2026-78237: Insufficient input validation in Admin By Request (ABR)
Published Aug 26, 2026
·Updated
Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into the sudoers file, resulting in persistent root access that remained effective after the ABR session ended.
Affected Software
1 affected component
Admin By Request (ABR)
Event History
Aug 26, 2026
CVE Published
via MITRE·07:24 AM
Data Sourced
via MITRE·07:24 AM
RemedyDescriptionSeverity
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must already have low-privileged local access to a system running Admin By Request (ABR). The attack vector is local and requires low privileges.
2
Does the resulting access end when the ABR session ends?
No. Malicious sudoers entries can provide persistent root access that remains effective after the ABR session has ended.