CVE-2026-40191 Details
Description
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.4-beta-1f46165, ClearanceKit's Endpoint Security event handler only checked the source path of dual-path file operations against File Access Authorization (FAA) rules and App Jail policies. The destination path was ignored entirely. This allowed any local process to bypass file-access protection by using rename, link, copyfile, exchangedata, or clone operations to place or replace files inside protected directories. This vulnerability is fixed in 5.0.4-beta-1f46165.
A vulnerability in ClearanceKit prior to version 5.0.4-beta-1f46165 allows local processes to bypass file-access protections in dual-path file operations. The issue arises because the Endpoint Security event handler only evaluated the source path against File Access Authorization (FAA) rules and App Jail policies, completely ignoring the destination path. This oversight enabled processes to move or copy files into protected directories without enforcement, undermining the integrity of the access control mechanisms.
Users can update to ClearanceKit version 5.0.4-beta-1f46165 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 10, 2026CISA-ADP
Assessed Apr 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/craigjbass/clearancekit/releases/tag/v5.0.4-1f46165 | [email protected] | Release NotesVendor |
| https://github.com/craigjbass/clearancekit/security/advisories/GHSA-92f3-38m7-579h | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Craig Bass ClearanceKit | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2026 | New CVE Received | [email protected] |
Volerion