CVE-2026-10610
Received Received - Intake

Local Privilege Escalation in Software Component

Vulnerability report for CVE-2026-10610, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: ESET

Description

Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
eset endpoint_security From 9.1.3100.0 (inc)
eset endpoint_security From 9.0.6400.0 (inc)
eset endpoint_security From 8.1.300.0 (inc)
eset cyber_security From 9.0.6300.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a local privilege escalation vulnerability in ESET's macOS security applications. It allows an unprivileged local user to execute arbitrary code with root permissions by exploiting a vulnerable helper binary in the ESET Uninstaller application. The flaw involves parsing directory names containing shell metacharacters, enabling command injection.

Detection Guidance

Check installed ESET macOS applications for versions below the fixed releases (Endpoint Security 9.1.3100.0+, 9.0.6400.0+, 8.1.300.0+ or Cyber Security 9.0.6300.0+). Inspect the ESET Uninstaller application bundle for the vulnerable helper binary.

Impact Analysis

If exploited, this vulnerability could lead to full system compromise. An attacker could gain complete control over the affected system by executing arbitrary code with elevated privileges. However, no active exploits in the wild have been detected as of now.

Compliance Impact

This vulnerability could lead to unauthorized root access on affected systems, potentially compromising sensitive data. For GDPR, this may result in unauthorized data access or processing, violating confidentiality principles. Under HIPAA, it could expose protected health information to unauthorized users, leading to compliance breaches.

Mitigation Strategies

Upgrade ESET Endpoint Security for macOS to version 9.1.3100.0 or later, 9.0.6400.0 or later, or 8.1.300.0 or later. For ESET Cyber Security, upgrade to version 9.0.6300.0 or later. If using legacy versions, update to a supported fixed release.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10610. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart