Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-281'

View all threats tagged with 'cwe-281'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-281

Threats Tagged 'cwe-281'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2025-14779: CWE-281: Assigning Permissions Instead of Checking Them in WSO2 WSO2 Identity ServerCVE-2025-14779
0

CVE-2025-14779 is a vulnerability in WSO2 Identity Server's Secret Type Management REST API where the deletion of a secret type does not properly enforce organizational boundaries. This flaw allows the deletion cascade to remove secrets across all organizations, not just the intended one. Exploitation requires delete permissions on the Secret Type Management REST API, which are typically restricted to administrators. The vulnerability can lead to unintended secret deletions, causing configuration failures, service interruptions, and denial-of-service conditions. The CVSS score is 3.8, indicating a low severity impact.

Join the discussion
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security UpdateCVE-2026-4360
0

This update includes the following RPMs: python3.10: * python3.10-3.10.20-3.1.hum1 (aarch64, x86_64) * python3.10-debug-3.10.20-3.1.hum1 (aarch64, x86_64) * python3.10-devel-3.10.20-3.1.hum1 (aarch64, x86_64) * python3.10-idle-3.10.20-3.1.hum1 (aarch64, x86_64) * python3.10-libs-3.10.20-3.1.hum1 (aarch64, x86_64) * python3.10-test-3.10.20-3.1.hum1 (aarch64, x86_64) * python3.10-tkinter-3.10.20-3.1.hum1 (aarch64, x86_64) * python3.10-3.10.20-3.1.hum1.src (src) Security Fix(es): python3.10: * CVE-2026-4360

Join the discussion
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private (CVE-2026-58510)CVE-2026-58510
0

Gitea contains a vulnerability in its API path for changing repository visibility from public to private. When this change is made via the REST API, stale watch records are not cleared, allowing users who lost access to still see metadata of the now-private repository in their subscription list. This leads to exposure of repository metadata and inflated watcher counts. The issue affects versions from v1.25.4 up to but not including v1.27.0. The severity is medium with limited confidentiality impact and no integrity or availability impact.

Join the discussion
Security fixes in step-ca-fips 0.30.2-r1 (CVE-2026-39828)CVE-2026-39828
0

Package step-ca-fips version 0.30.2-r1 fixes 16 vulnerabilities: CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832...

Join the discussion
CVE-2026-39832: CWE-281: Improper Preservation of Permissions in golang.org/x/crypto golang.org/x/crypto/ssh/agentCVE-2026-39832
0

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: cwe-281
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses