Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-15'

View all threats tagged with 'cwe-15'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-15

Threats Tagged 'cwe-15'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-16708: CWE-15 External Control of System or Configuration Setting in IBM Db2 Mirror for iCVE-2026-16708
0

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration.

Join the discussion
CVE-2026-19884: CWE-829 in Eclipse Foundation Eclipse TheiaCVE-2026-19884
0

In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. This affects applications built on Theia that include the git integration, such as the Theia IDE. Both Theia's own `@theia/git` extension and the builtin VS Code `git` extension run git commands such as `git status` as soon as a repository is detected. Since git honors repository-local configuration, a folder containing an attacker-controlled `.git/config` with `core.fsmonitor` (or a comparable hook-like setting) causes the configured command to be executed. The configuration can be delivered by burying a bare repository inside a regular repository (OVE-20210718-0001), so cloning an attacker-supplied repository and opening it in a Theia-based application is sufficient to execute arbitrary commands with the privileges of the user, without any confirmation prompt. As of 1.70.0, plugins that declare `capabilities.untrustedWorkspaces.supported: false`, which includes the builtin git extension, are no longer loaded or activated in an untrusted workspace, and the deprecated `@theia/git` extension has been removed, so no git command is executed against an untrusted folder.

Join the discussion
CVE-2026-73661: CWE-15: External Control of System or Configuration Setting in FreePBX frameworkCVE-2026-73661
0

CVE-2026-73661 is a high-severity vulnerability in the FreePBX Framework module that allows an authenticated user with backup-restore or write access to crafted backup files to disable authentication during restoration. This occurs because the restore process permits restoring the hidden AUTHTYPE setting with the value 'none', bypassing the user interface's removal of this insecure setting. The issue affects FreePBX versions prior to 16.0.47 and 17.0.30 and is fixed in these versions.

Join the discussion
CVE-2026-66065: CWE-15: External Control of System or Configuration Setting in Q00 ouroborosCVE-2026-66065
0

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Several execution-routing keys of the same RCE class were omitted, so a malicious cloned repo can still reach arbitrary command execution by shipping a .env (auto-loaded at import, with no review step). The CVE-2026-47211 fix added _UNTRUSTED_ENV_DENYLIST to stop an untrusted project-directory .env from redirecting execution, but it did not account for all keys. The backend config-home and MCP/plugin roots bypass the approval gate by pointing the nested agent, MCP servers, and plugin roster at attacker config. Other variables re-enable blocked local transports, replace sub-agent prompts, switch backends, and lower tool approval classes, further weakening the approval gate. This issue has been fixed in version 0.42.1.

Join the discussion
CVE-2026-56567: CWE-15 External Control of System or Configuration Setting in HCL Software HCL iControlCVE-2026-56567
0

HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: cwe-15
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses