PT-2026-32041 · Unknown · Clearancekit

Published

2026-04-10

·

Updated

2026-04-11

·

CVE-2026-40191

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ClearanceKit versions prior to 5.0.4-beta-1f46165
Description ClearanceKit monitors file system access on macOS and applies access policies per process. Before version 5.0.4-beta-1f46165, the Endpoint Security event handler only verified the source path of file operations (rename, link, copyfile, exchangedata, clone) against File Access Authorization (FAA) rules and App Jail policies, neglecting the destination path. This allowed local processes to circumvent file access restrictions by placing or replacing files within protected directories.
Recommendations Update to version 5.0.4-beta-1f46165 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40191

Affected Products

Clearancekit