CVE-2026-39118

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke restricted agent functionality.

Published 2026-06-15. Last modified 2026-06-17.