Threats Tagged 'cwe-59'
View all threats tagged with 'cwe-59'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-59'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-12391: CWE-59 Improper link resolution before file access ('link following') in Canonical ubuntu-pro-client (ubuntu-advantage-tools)CVE-2026-12391 0 An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying the file type or ownership. An unprivileged local attacker can exploit this behavior by creating a symbolic link (symlink) at a predictable destination path pointing to an arbitrary, root-readable file (such as /etc/shadow or private files within /root). When a root administrator or operator subsequently executes the pro collect-logs command, the tool follows the user-controlled symlink, reads the target file, and compresses its contents into the resulting diagnostic support archive. Because the output archive remains readable by the unprivileged user, the attacker can extract and read the sensitive root-owned files, leading to a complete information disclosure of system secrets. Join the discussion | CVE Database V5 | 07/16/2026, 12:17:01 UTC Added: 07/16/2026, 12:48:28 UTC |
CVE-2026-50526: CWE-59: Improper Link Resolution Before File Access ('Link Following') in Microsoft .NET 10.0CVE-2026-50526 0 Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally. Join the discussion | CVE Database V5 | 07/14/2026, 19:29:54 UTC Added: 07/14/2026, 19:33:59 UTC |
CVE-2026-50469: CWE-59: Improper Link Resolution Before File Access ('Link Following') in Microsoft Windows 10 Version 1809CVE-2026-50469 0 Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally. Join the discussion | CVE Database V5 | 07/14/2026, 17:07:13 UTC Added: 07/14/2026, 17:49:23 UTC |
CVE-2026-50438: CWE-59: Improper Link Resolution Before File Access ('Link Following') in Microsoft Microsoft PC ManagerCVE-2026-50438 0 Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. Join the discussion | CVE Database V5 | 07/14/2026, 17:07:34 UTC Added: 07/14/2026, 17:49:19 UTC |
CVE-2026-58636: CWE-59: Improper Link Resolution Before File Access ('Link Following') in Microsoft Microsoft PC ManagerCVE-2026-58636 0 Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally. Join the discussion | CVE Database V5 | 07/14/2026, 17:05:36 UTC Added: 07/14/2026, 17:19:00 UTC |
CVE-2026-50364: CWE-59: Improper Link Resolution Before File Access ('Link Following') in Microsoft Windows 10 Version 21H2CVE-2026-50364 0 Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally. Join the discussion | CVE Database V5 | 07/14/2026, 17:06:18 UTC Added: 07/14/2026, 17:18:46 UTC |
CVE-2026-49791: CWE-59: Improper Link Resolution Before File Access ('Link Following') in Microsoft Windows 10 Version 1607CVE-2026-49791 0 Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. Join the discussion | CVE Database V5 | 07/14/2026, 17:05:53 UTC Added: 07/14/2026, 17:18:37 UTC |
CVE-2026-49180: CWE-59: Improper Link Resolution Before File Access ('Link Following') in Microsoft Windows 10 Version 1607CVE-2026-49180 0 Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 07/14/2026, 17:05:48 UTC Added: 07/14/2026, 17:18:35 UTC |
CVE-2026-49176: CWE-269: Improper Privilege Management in Microsoft Windows 10 Version 1607CVE-2026-49176 0 Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally. Join the discussion | CVE Database V5 | 07/14/2026, 17:04:30 UTC Added: 07/14/2026, 17:18:35 UTC |
CVE-2026-15392: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in HMBRAND DBD::FileCVE-2026-15392 0 DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the configured f_dir and f_dir_search directories. Callers of file-based drivers can read or write files outside of the data directory. Join the discussion | CVE Database V5 | 07/14/2026, 15:34:01 UTC Added: 07/14/2026, 15:48:11 UTC |
Showing 1 to 10 of 38 results