Threats Tagged 'cwe-285'
View all threats tagged with 'cwe-285'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-285'
Click on any threat for detailed analysis and mitigation recommendations
MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_id}/chat/{chat_id}/share_chat verifies that a conversation exists but does not verify that it belongs to the authenticated chat_user_id or to the application bound to the caller's token. An attacker with any chat token and a known victim chat_id can create an unauthenticated public ChatShareLink exposing the victim's conversation and can create PublicFileAccess state that makes associated files retrievable without credentials, with no available revoke path. No fixed version is available as of this review. Join the discussion | CVE Database V5 | 09/21/2026, 20:43:27 UTC Added: 09/21/2026, 22:12:11 UTC |
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects /@warpgate/admin/api/recordings/{uuid}/stream only with session authentication and omits require_admin_permission for AdminPermission::RecordingsView. Any authenticated regular user who identifies an active recording can subscribe to its WebSocket and receive real-time terminal input and output from proxied SSH, MySQL, or PostgreSQL sessions, including credentials, commands, and other sensitive data belonging to users and administrators. This issue is fixed in version 0.25.6. Join the discussion | CVE Database V5 | 09/21/2026, 18:49:45 UTC Added: 09/21/2026, 19:02:22 UTC |
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization. Join the discussion | GCVE Database | 09/18/2026, 21:32:27 UTC Added: 09/19/2026, 01:26:54 UTC |
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization. Join the discussion | GCVE Database | 09/18/2026, 21:32:26 UTC Added: 09/19/2026, 01:27:01 UTC |
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization. Join the discussion | GCVE Database | 09/18/2026, 21:32:26 UTC Added: 09/19/2026, 01:26:58 UTC |
zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to the push action, so DELETE requests are not checked for the distinct delete permission. Bearer-authenticated requests also bypass the fine-grained DistSpecAuthzHandler path in pkg/api/authz.go, while DeleteManifest and DeleteBlob perform no independent delete-permission check. A remote attacker with a bearer token limited to pull and push actions can therefore delete manifests and blobs within the token's repository scope, making images unavailable and allowing repository history to be altered despite the token lacking delete authorization. This issue is fixed in version 2.1.18. Join the discussion | CVE Database V5 | 09/18/2026, 16:55:22 UTC Added: 09/18/2026, 17:02:21 UTC |
WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation write routes authenticate account viewers but do not enforce the agent role before using a service-role database client that bypasses row-level security. In src/app/api/flows/[id]/route.ts, src/app/api/flows/[id]/activate/route.ts, and src/app/api/flows/route.ts, a viewer can create, edit, activate, or delete flows because membership-only checks are followed by service-role writes. In src/app/api/automations/route.ts and src/app/api/automations/engine/route.ts, a viewer can create active automations and trigger outbound WhatsApp actions without the role required by the underlying write policies. This can permit unauthorized workflow changes, destructive flow deletion, and outbound actions from a role intended to be read-only. This vulnerability is fixed with commit 03e851bea56dcf6bb21ff1b80ba531372bf3269f. Join the discussion | CVE Database V5 | 09/18/2026, 16:45:27 UTC Added: 09/18/2026, 17:02:21 UTC |
0 IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks. Join the discussion | CVE Database V5 | 09/18/2026, 15:47:15 UTC Added: 09/18/2026, 16:02:21 UTC |
0 HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged roles. Join the discussion | CVE Database V5 | 09/18/2026, 07:54:03 UTC Added: 09/18/2026, 08:02:18 UTC |
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network. Join the discussion | GCVE Database | 09/17/2026, 23:04:46 UTC Added: 09/18/2026, 01:01:05 UTC |
Showing 1 to 10 of 338 results