Passwordless access that adapts to every context
Manage every device with one lightweight agent
Stay audit-ready with continuous evidence collection
Automating compliance, insights, and actions from a single interface.
We’ve released Kandji Agent 4.7.5 (5374).
This release includes miscellaneous bug fixes and performance improvements.
Security
CVE-2026-39118 — An access control issue existed in the Kandji Agent (macOS). A local attacker with standard user privileges could invoke restricted functionality. This issue was addressed with improved validation.
Affected: Kandji Agent (macOS) before 4.7.5 (5374)
Fixed in: 4.7.5 (5374), available March 25, 2026 (this version)
Severity: CVSS 3.1 — 6.1 (Medium) · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Credit: Iru thanks Hillel Pinto of XM Cyber for reporting this issue.
Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.