High severity8.4NVD Advisory· Published Jun 15, 2026· Updated Jun 16, 2026
CVE-2026-39118
CVE-2026-39118
Description
An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke restricted agent functionality.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <4.7.5(5374)
Patches
Vulnerability mechanics
References
1News mentions
3- macOS Flaw Lets Standard Users Disable EDR and MDMInfosecurity Magazine · Jun 25, 2026
- macOS Weaknesses Chained to Silently Disable Endpoint Security AgentsSecurityWeek · Jun 24, 2026
- Apple's MacOS Gap Lets Users Disable Security ToolsDark Reading · Jun 24, 2026