CVE-2026-39875

HIGH

Apple macOS - Incorrect Default Permissions

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-39875. PoCs published by mac-123456789-lab.

AI-analyzed exploit summary This PoC exploits a local privilege escalation (LPE) vulnerability in macOS CUPS (Common UNIX Printing System) by abusing improper authorization token handling and printer device URI manipulation to write arbitrary files (e.g., to `/etc/sudoers.d/`), granting the attacker passwordless sudo access.

Description

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

Exploits (1)

github WORKING POC
by mac-123456789-lab · pythonpoc
https://github.com/mac-123456789-lab/CVE-2026-39875-macOS-CUPS-LPE

This PoC exploits a local privilege escalation (LPE) vulnerability in macOS CUPS (Common UNIX Printing System) by abusing improper authorization token handling and printer device URI manipulation to write arbitrary files (e.g., to `/etc/sudoers.d/`), granting the attacker passwordless sudo access.

Classification
Working Poc 98%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: macOS CUPS (versions affected: Sequoia 15.7.5, Sonoma 14.8.5, Tahoe 26.4.1)
No auth needed
Prerequisites: CUPS service running and accessible on localhost:631 · Ability to bind to a local port (9189) for token capture · Non-SIP-protected file paths writable by the CUPS process
mistral-large-3 · analyzed Jul 28, 2026 Full analysis →

Scores

CVSS v3 7.8
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Products (3)
Apple/macOS < 14.8.8
Apple/macOS < 15.7.8
Apple/macOS < 26.6
Published Jul 27, 2026
Tracked Since Jul 28, 2026