PT-2026-32041 · Unknown · Clearancekit
Published
2026-04-10
·
Updated
2026-04-11
·
CVE-2026-40191
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ClearanceKit versions prior to 5.0.4-beta-1f46165
Description
ClearanceKit monitors file system access on macOS and applies access policies per process. Before version 5.0.4-beta-1f46165, the Endpoint Security event handler only verified the source path of file operations (rename, link, copyfile, exchangedata, clone) against File Access Authorization (FAA) rules and App Jail policies, neglecting the destination path. This allowed local processes to circumvent file access restrictions by placing or replacing files within protected directories.
Recommendations
Update to version 5.0.4-beta-1f46165 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clearancekit