PT-2026-34038 · Craigjbass · Clearancekit
Published
2026-04-21
·
Updated
2026-04-21
·
CVE-2026-40604
CVSS v4.0
8.2
High
| AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
ClearanceKit versions prior to 5.0.6
Description
The opfilter Endpoint Security system extension (bundle ID 'uk.craigbass.clearancekit.opfilter') can be suspended using SIGSTOP or kill -STOP, or terminated using SIGKILL/SIGTERM, by any process with root privileges. When the extension is suspended, all AUTH Endpoint Security events time out and default to allow, which silently disables the enforcement of file-access policies.
Recommendations
Update to version 5.0.6.
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clearancekit