Access Control Vulnerability in ClearanceKit on macOS by Craig J. Bass
CVE-2026-47134

6.9MEDIUM

Key Information:

Vendor

Craigjbass

Vendor
CVE Published:
20 July 2026

What is CVE-2026-47134?

The ClearanceKit application for macOS implements file-system access event interceptions and enforces access policies on a per-process basis. A significant flaw exists in the handling of the ECDSA private key utilized for signing its policy database, where the access controls originally intended for secure key management are not applied properly due to a bug affecting legacy System Keychain items. This oversight allows any process with root privileges to utilize the exposed key for unauthorized signature generation over potentially harmful policy data. ClearanceKit version 5.0.10 addresses this vulnerability, but until then, the lack of defined access controls poses a significant risk.

Affected Version(s)

clearancekit < 5.0.10

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.