Description
This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758.
Published: 2026-08-13
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a normal user to disable the Forcepoint One Endpoint SafariExtension, which is responsible for enforcing data loss prevention rules for Safari on macOS. Disabling the extension removes the active protection layer and enables the user to transmit or otherwise access enterprise data that would normally be blocked. The flaw is rooted in the lack of proper validation of the extension’s enabled status (CWE‑754).

Affected Systems

Forcepoint One Endpoint for macOS versions prior to v26.04.5758 are affected. The advisory does not explicitly state which macOS releases are supported, so that portion is inferred.

Risk and Exploitability

The CVSS score of 4.8 classifies the issue as moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV. The vulnerability allows a non‑admin user with local access to disable the SafariExtension. The inference that widespread exploitation is limited is based on the local nature of the attack, but this is not directly stated in the source.

Generated by OpenCVE AI on August 13, 2026 at 11:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Forcepoint One Endpoint to version v26.04.5758 or later, which restricts extension disabling to admin users only
  • Restart the computer after the update to ensure the SafariExtension is re‑enabled and the protection is active
  • If an immediate update is not possible, manually re‑enable the SafariExtension through the application settings and restrict local user rights to prevent future disabling attempts

Generated by OpenCVE AI on August 13, 2026 at 11:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Forcepoint
Forcepoint f1e Mac
Vendors & Products Forcepoint
Forcepoint f1e Mac

Thu, 13 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Title Forcepoint One Endpoint SafariExtension Disable Bypass

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758.
Weaknesses CWE-754
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Forcepoint F1e Mac
cve-icon MITRE

Status: PUBLISHED

Assigner: forcepoint

Published:

Updated: 2026-08-13T14:41:31.917Z

Reserved: 2026-06-11T11:18:47.142Z

Link: CVE-2026-11970

cve-icon Vulnrichment

Updated: 2026-08-13T14:41:27.432Z

cve-icon NVD

Status : Received

Published: 2026-08-13T10:17:10.060

Modified: 2026-08-13T15:19:27.940

Link: CVE-2026-11970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T13:20:17Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions