CVE-2026-40604 affects ClearanceKit, a macOS security extension that enforces file-system access policies on a per-process basis. Prior to version 5.0.6, the opfilter Endpoint Security system extension (uk.craigbass.clearancekit.opfilter) can be suspended or terminated by any root-level process, causing all authorization events to default to allow status and effectively disabling the application's file-access controls. The vulnerability requires root-level privileges to exploit, making the attack complexity moderately elevated. However, the impact is significant: successful exploitation completely circumvents ClearanceKit's security policy enforcement through suspension of critical system processes. The CVSS score is unavailable, though the FAUCET Risk Score of 40.0/100 indicates moderate concern. There is currently no evidence of active exploitation in the wild. The vulnerability is not listed on the Known Exploited Vulnerabilities catalog, and community attention remains low as reflected in the inactive Hot List status. The extremely low EPSS score of 0.00017 suggests this vulnerability is not a priority target compared to other disclosed vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0.6CPE matchmatch criteria | cpe:2.3:a:craigjbass:clearancekit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.