Threats Tagged 'cwe-281'
View all threats tagged with 'cwe-281'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-281'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2025-14779: CWE-281: Assigning Permissions Instead of Checking Them in WSO2 WSO2 Identity ServerCVE-2025-14779 0 CVE-2025-14779 is a vulnerability in WSO2 Identity Server's Secret Type Management REST API where the deletion of a secret type does not properly enforce organizational boundaries. This flaw allows the deletion cascade to remove secrets across all organizations, not just the intended one. Exploitation requires delete permissions on the Secret Type Management REST API, which are typically restricted to administrators. The vulnerability can lead to unintended secret deletions, causing configuration failures, service interruptions, and denial-of-service conditions. The CVSS score is 3.8, indicating a low severity impact. Join the discussion | CVE Database V5 | 08/06/2026, 07:33:10 UTC Added: 08/06/2026, 08:11:46 UTC |
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security UpdateCVE-2026-4360 0 This update includes the following RPMs: python3.10: * python3.10-3.10.20-3.1.hum1 (aarch64, x86_64) * python3.10-debug-3.10.20-3.1.hum1 (aarch64, x86_64) * python3.10-devel-3.10.20-3.1.hum1 (aarch64, x86_64) * python3.10-idle-3.10.20-3.1.hum1 (aarch64, x86_64) * python3.10-libs-3.10.20-3.1.hum1 (aarch64, x86_64) * python3.10-test-3.10.20-3.1.hum1 (aarch64, x86_64) * python3.10-tkinter-3.10.20-3.1.hum1 (aarch64, x86_64) * python3.10-3.10.20-3.1.hum1.src (src) Security Fix(es): python3.10: * CVE-2026-4360 Join the discussion | GCVE Database | 07/29/2026, 13:40:53 UTC Added: 07/30/2026, 05:46:50 UTC |
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private (CVE-2026-58510)CVE-2026-58510 0 Gitea contains a vulnerability in its API path for changing repository visibility from public to private. When this change is made via the REST API, stale watch records are not cleared, allowing users who lost access to still see metadata of the now-private repository in their subscription list. This leads to exposure of repository metadata and inflated watcher counts. The issue affects versions from v1.25.4 up to but not including v1.27.0. The severity is medium with limited confidentiality impact and no integrity or availability impact. Join the discussion | GCVE Database | 08/13/2026, 16:44:58 UTC Added: 07/22/2026, 00:11:14 UTC |
Security fixes in step-ca-fips 0.30.2-r1 (CVE-2026-39828)CVE-2026-39828 0 Package step-ca-fips version 0.30.2-r1 fixes 16 vulnerabilities: CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832... Join the discussion | GCVE Database | 05/22/2026, 02:31:26 UTC Added: 07/21/2026, 20:03:21 UTC |
CVE-2026-39832: CWE-281: Improper Preservation of Permissions in golang.org/x/crypto golang.org/x/crypto/ssh/agentCVE-2026-39832 0 When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them. Join the discussion | GCVE Database | 05/22/2026, 02:31:26 UTC Added: 07/21/2026, 20:03:21 UTC |
Showing 1 to 5 of 5 results