High severity7.5NVD Advisory· Published Feb 25, 2019· Updated Jun 17, 2026
CVE-2019-9146
CVE-2019-9146
Description
Jamf Self Service 10.9.0 allows man-in-the-middle attackers to obtain a root shell by leveraging the "publish Bash shell scripts" feature to insert "/Applications/Utilities/Terminal app/Contents/MacOS/Terminal" into the TCP data stream.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:jamf:self_service:10.9.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/PAGalaxyLab/VulInfo/blob/master/JAMF/JAMF%20software%20%20local%20permission%20promotion%20vulnerability.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.