OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-4556

HIGH · CVSS 7.8 EPSS 0.89% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A local privilege escalation vulnerability exists in the com.extegrity.LogTool privileged helper of Exam4, allowing attackers to exploit the copyConsoleIntoFileFromStartDate: method to inject arbitrary commands due to inadequate input sanitization. This flaw enables local attackers to execute commands with root privileges, posing a significant security risk. Organizations using Exam4 should prioritize patching this vulnerability to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-4556
Severity
HIGH
CVSS
7.8
EPSS
0.89%

Original NVD Description

Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privileged helper, which communicates with the application via XPC. The [ConsoleLogHelper copyConsoleIntoFileFromStartDate:] method executes a syslog command using attacker-controlled parameters without proper sanitization, enabling command injection. Successful exploitation allows a local attacker to execute arbitrary commands with root privileges through LaunchSynchronous.