Craigjbass's vulnerability footprint centers on ClearanceKit, a specialized authorization and access-control product where the durable signal is a concentration of privilege and authorization weaknesses—missing authorization checks, improper privilege management, incorrect authorization logic, and protection mechanism failures. These recurring patterns reflect the core function of access-control software and the inherent complexity of enforcing authorization boundaries consistently across a codebase. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Craigjbass over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33631HIGH ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. In versions on the 4.1 branch and earlier, the opfilter Endpoint Security syste | Mar 26, 2026 | 8.7 | 29 | NO | NO |
CVE-2026-33632HIGH ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.4, two file operation event types — ES_EVENT_TYPE_AUTH_EXC | Mar 26, 2026 | 7.8 | 25 | NO | NO |
CVE-2026-40599HIGH ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, ClearanceKit incorrectly treats a process with an empty Team ID | Apr 21, 2026 | 7.1 | 24 | NO | NO |
CVE-2026-34218MEDIUM ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.14, two related startup defects created a window during wh | Mar 31, 2026 | 5.5 | 20 | NO | NO |
CVE-2026-40604MEDIUM ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.6, the opfilter Endpoint Security system extension (bundle ID uk.c | Apr 21, 2026 | 4.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Craigjbass.
Media articles that mention a CVE ID that affects a product developed by Craigjbass — matched by CVE ID, not by vendor name.