Threats Tagged 'cwe-552'
View all threats tagged with 'cwe-552'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-552'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-8715: CWE-552: Files or Directories Accessible to External Parties in HashiCorp ToolingCVE-2026-8715 0 Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0. Join the discussion | CVE Database V5 | 08/13/2026, 20:27:39 UTC Added: 08/13/2026, 20:42:03 UTC |
CVE-2026-73653: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in vitest-dev vitestCVE-2026-73653 0 Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root. A client that can reach the Browser Mode API can read arbitrary local files, create or overwrite image and trace files, or delete files accessible to the Vitest process even when allowWrite is false. This issue is fixed in versions 3.2.7, 4.1.10, and 5.0.0-beta.6. Join the discussion | CVE Database V5 | 08/13/2026, 18:19:00 UTC Added: 08/13/2026, 18:41:55 UTC |
CVE-2026-14849: CWE-552 Files or Directories Accessible to External Parties in Paid Membership SubscriptionsCVE-2026-14849 0 A vulnerability in the Paid Membership Subscriptions WordPress plugin before version 3.0.7 allows unauthenticated users to download exported member and payment data files. These files, containing personally identifiable information (PII), are written to a predictable location in the uploads directory without proper access protection. This exposure can occur while the export artifact is present on the server. Join the discussion | CVE Database V5 | 07/31/2026, 06:00:07 UTC Added: 07/31/2026, 06:37:43 UTC |
CVE-2026-11841: CWE-552 Files or directories accessible to external parties in SICK AG InspectorP61xCVE-2026-11841 0 An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment. Join the discussion | CVE Database V5 | 07/28/2026, 09:25:36 UTC Added: 07/28/2026, 10:22:59 UTC |
CVE-2026-57990: CWE-552: Files or Directories Accessible to External Parties in Microsoft Microsoft Edge (Chromium-based)CVE-2026-57990 0 Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. Join the discussion | GCVE Database | 07/26/2026, 17:22:14 UTC Added: 07/26/2026, 22:46:11 UTC |
CVE-2026-57990: CWE-552: Files or Directories Accessible to External Parties in Microsoft Microsoft Edge (Chromium-based)CVE-2026-57990 0 Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 07/26/2026, 17:22:14 UTC Added: 07/26/2026, 17:53:15 UTC |
Showing 1 to 6 of 6 results