Junglewise Threat Intelligence

CVE-2026-40191: craigjbass ClearanceKit authorization bypass in Endpoint Security handler

CVE-2026-40191 · Severity: info · CVSS 6.8 · Published 2026-04-10

Technologies: Craigjbass ClearanceKit. Vendors: Craigjbass.

Executive brief

ClearanceKit is a security tool for macOS that controls which applications can access specific files and folders. A flaw in how it monitors file movements allowed unauthorized programs to bypass these protections by renaming or moving files into restricted areas. This could allow a malicious user or program to tamper with protected data or escape security sandboxes, potentially compromising the integrity of the system.

Technical details

ClearanceKit's Endpoint Security (ES) event handler incorrectly processed dual-path file operations (rename, link, copyfile, exchangedata, and clone). While the handler checked the source path against File Access Authorization (FAA) rules and App Jail policies, it entirely ignored the destination path. A local attacker with low privileges can exploit this by moving or copying files into protected directories or out of restricted 'jails' without triggering a denial. This vulnerability effectively allows for the silent replacement of protected files and the circumvention of path-based security restrictions. The issue is resolved in version 5.0.4 and specific beta releases by ensuring both source and destination paths are validated.

Affected products

  • craigjbass ClearanceKit <= 5.0.3, v5.0.4-beta-2441e70 and earlier

Timeline

  • 2026-04-09: patched: Fixed in version 5.0.4 and beta 1f46165
  • 2026-04-10: disclosed: CVE-2026-40191 published

References