A vulnerability, which was classified as problematic, was found in sparkle-project Sparkle up to 2.9.1. This impacts the function shouldAcceptNewConnection of the file Autoupdate/AppInstaller.m of the component Autoupdate. The manipulation results in Local Privilege Escalation.

This vulnerability was named CVE-2026-47122. The attack needs to be approached locally. There is no available exploit.