Skip to content

Kandji Agent Release 4.7.5 (5374)

We’ve released Kandji Agent 4.7.5 (5374).

This release includes miscellaneous bug fixes and performance improvements.

Security

CVE-2026-39118 — An access control issue existed in the Kandji Agent (macOS). A local attacker with standard user privileges could invoke restricted functionality. This issue was addressed with improved validation.

Affected: Kandji Agent (macOS) before 4.7.5 (5374)

Fixed in: 4.7.5 (5374), available March 25, 2026 (this version)

Severity: CVSS 3.1 — 6.1 (Medium) · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

Credit: Iru thanks Hillel Pinto of XM Cyber for reporting this issue.

Stay up to date

Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.