๐Ÿ” CVE Alert

CVE-2026-4556

HIGH 7.8

macOS Exam4 Local Privilege Escalation via Command Injection

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privileged helper, which communicates with the application via XPC. The [ConsoleLogHelper copyConsoleIntoFileFromStartDate:] method executes a syslog command using attacker-controlled parameters without proper sanitization, enabling command injection. Successful exploitation allows a local attacker to execute arbitrary commands with root privileges through LaunchSynchronous.

CWE CWE-78
Vendor extegrity
Product exam4
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for extegrity exam4

Be the first to know when new high vulnerabilities affecting extegrity exam4 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Extegrity / Exam4
0 โ‰ค 25.12.28.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
pentraze.com: https://pentraze.com/vulnerability-reports

Credits

Carlos Garrido of Pentraze Cybersecurity