CVE-2026-33632: Endpointsecurity Missing Exchangedata Clone

The EndpointSecurity event array monitors file creation or modification (e.g., AUTH_CREATE or AUTH_COPYFILE) but lacks subscriptions for ES_EVENT_TYPE_AUTH_EXCHANGEDATA or ES_EVENT_TYPE_AUTH_CLONE. This pattern is associated with an incomplete file monitoring scope, allowing attackers to bypass the authorization boundary via exchangedata or clonefile system

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Swift
greprules fetch cve-2026-33632-endpointsecurity-missing-exchangedata-clone --engine opengrep

Description

The EndpointSecurity event array monitors file creation or modification (e.g., AUTH_CREATE or AUTH_COPYFILE) but lacks subscriptions for ES_EVENT_TYPE_AUTH_EXCHANGEDATA or ES_EVENT_TYPE_AUTH_CLONE. This pattern is associated with an incomplete file monitoring scope, allowing attackers to bypass the authorization boundary via exchangedata or clonefile system