Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 11 Sep 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Waves Audio
Waves Audio waves Central |
|
| Vendors & Products |
Waves Audio
Waves Audio waves Central |
Tue, 08 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Waves Central for macOS contains a local privilege escalation in the privileged helper service. The helper authorizes connecting XPC clients by comparing the caller's code-signing certificate chain for equality with its own, rather than validating the caller against a pinned code requirement (application identifier and Team ID). A local, authenticated user can execute code within the vendor-signed process, satisfy the helper's client check, and cause the helper to execute a script with root privileges. Fixed in 17.0. | |
| Title | Waves Central local privilege escalation via Improper XPC Client Authentication in macOS | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-09-08T20:22:57.586Z
Reserved: 2026-09-08T14:09:48.155Z
Link: CVE-2026-86819
No data.
Status : Awaiting Analysis
Published: 2026-09-08T21:18:47.520
Modified: 2026-09-09T15:38:39.083
Link: CVE-2026-86819
No data.
OpenCVE Enrichment
Updated: 2026-09-11T05:00:12Z