CVE-2026-34218
Severity CVSS v4.0:
MEDIUM
Type:
CWE-269
Improper Privilege Management
Publication date:
31/03/2026
Last modified:
06/04/2026
Description
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.14, two related startup defects created a window during which only the single compile-time baseline rule was enforced by opfilter. All managed (MDM-delivered) and user-defined file-access rules were not applied until the user interacted with policies through the GUI, triggering a policy mutation over XPC. This issue has been patched in version 4.2.14.
Impact
Base Score 4.0
6.30
Severity 4.0
MEDIUM
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:craigjbass:clearancekit:*:*:*:*:*:*:*:* | 4.2.14 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



