๐Ÿ” CVE Alert

CVE-2026-34218

MEDIUM 5.5

ClearanceKit: Managed and user-defined policy rules not enforced between opfilter start and first policy modification

CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
2th

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.14, two related startup defects created a window during which only the single compile-time baseline rule was enforced by opfilter. All managed (MDM-delivered) and user-defined file-access rules were not applied until the user interacted with policies through the GUI, triggering a policy mutation over XPC. This issue has been patched in version 4.2.14.

CWE CWE-269
Vendor craigjbass
Product clearancekit
Published Mar 31, 2026
Last Updated Apr 2, 2026
Stay Ahead of the Next One

Get instant alerts for craigjbass clearancekit

Be the first to know when new medium vulnerabilities affecting craigjbass clearancekit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

craigjbass / clearancekit
< 4.2.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/craigjbass/clearancekit/security/advisories/GHSA-fpmv-5wgw-qhhr github.com: https://github.com/craigjbass/clearancekit/commit/56d617b778c571e3c29b803636d9807940992daa github.com: https://github.com/craigjbass/clearancekit/commit/ddfdacb2633681bbd9c2f41dbd536ea039386628