Skip to main content

Threats Tagged 'cwe-424'

View all threats tagged with 'cwe-424'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-424

Threats Tagged 'cwe-424'

Click on any threat for detailed analysis and mitigation recommendations

Bulletin ID: 2026-128-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/07/2026 13:00 PM PDT Description: Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed. Query results, credentials, and Amazon S3 data were not affected. No customer action is required. Resolution: This issue was addressed service-side on September 1, 2026. Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Join the discussion
0

A caller who can invoke the convert_playwright_script prompt in mcp-k6 can pass a bare file path as the playwright_script argument and receive the contents of any file readable by the user running the server, including SSH keys and cloud credentials in that user's home directory (path traversal). The working-directory restriction applied to '@'-prefixed paths can also be bypassed with a symbolic link inside the working directory that points outside it.

Join the discussion

CVE-2026-82586 is a high-severity vulnerability in ash-project's ash_lua component that allows Lua scripts to bypass field exposure restrictions. The vulnerability arises because the read operation in AshLua.Runtime resolves field names without consulting the exposed-field allow-list, enabling scripts to read any attribute, including private sensitive fields like hashed passwords. This affects versions from 0.1.0 up to but not including 0.2.1.

Join the discussion

CVE-2026-82754 is an improper protection of alternate path vulnerability in ash-project's ash_authentication_oauth2_server. The OAuth endpoints intended to be accessed under the /oauth prefix are also accessible under the /.well-known prefix due to route forwarding behavior. This allows bypassing security controls such as WAF rules, rate limits, or authentication exemptions that are scoped only to the canonical /oauth prefix. The vulnerability affects versions from 0.1.0 up to but not including 0.3.1.

Join the discussion

CVE-2026-86145 is a high-severity vulnerability in PCRE2 versions 10.32 up to but not including 10.48. It involves an out-of-bounds write in the pcre2_dfa_match function due to improper size checking when reusing a cached workspace block during recursive DFA matching. Exploitation requires an attacker-controlled regular expression or a recursive pattern combined with a small heap limit set via the API.

Join the discussion

Bulletin ID: 2026-007-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/16 09:15 AM PDT Description: The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables AI assistants to interact with AWS services and resources through AWS CLI commands. It provides programmatic access to manage your AWS infrastructure while maintaining proper security controls. This server acts as a bridge between AI assistants and AWS services, allowing you to create, update, and manage AWS resources across all available services. The server includes a configurable file access feature that controls how AWS CLI commands interact with the local file system. By default, file operations are restricted to a designated working directory (workdir), but this can be configured to allow unrestricted file system access (unrestricted) or to block all local file path arguments entirely (no-access). We identified CVE-2026-4270: Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and = 0.2.14, < 1.3.9 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Join the discussion

Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

Join the discussion

CVE-2026-66756 is an Improper Protection of Alternate Path vulnerability in Apache Tika affecting versions from 4.0.0-alpha-1 up to but not including 4.0.0-beta-1. This vulnerability allows unauthorized access or manipulation due to insufficient protection of alternate file paths. The issue is resolved in version 4.0.0-beta-1, which users are advised to upgrade to.

Join the discussion

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.

Join the discussion

A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.

Join the discussion

Showing 1 to 10 of 20 results

Filters:Tag: cwe-424
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses