Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-653'

View all threats tagged with 'cwe-653'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-653

Threats Tagged 'cwe-653'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-62246: CWE-284: Improper Access Control in clastix kamajiCVE-2026-62246
0

Kamaji, a Hosted Control Plane Manager for Kubernetes, has an improper access control vulnerability prior to version 26.7.4-edge. The issue arises from a lossy normalization process that causes distinct tenants with colliding normalized identifiers to share control-plane state. This allows unauthorized tenants to read, modify, or destroy another tenant's Kubernetes data. The vulnerability is identified as CVE-2026-62246 and has a high severity score of 8.5. The problem is fixed in version 26.7.4-edge.

Join the discussion
CVE-2026-65635: CWE-653 Improper Isolation or Compartmentalization in malach-it borutaCVE-2026-65635
0

Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attackers to register OpenID Connect clients with administrative privileges through the dynamic client registration entry point. Boruta.Openid.register_client/3 forwards caller-supplied registration parameters to the administrative client creation path without a public/admin field-level allowlist, so an unauthenticated registrant can set security-sensitive attributes including supported grant types, authorized scopes, PKCE enforcement, public refresh and revocation behavior, token lifetimes, and signing settings. The library does not distinguish between metadata a public registrant is allowed to set and administrative controls that should require operator approval. This vulnerability is associated with program files lib/boruta/openid.ex and program routines 'Elixir.Boruta.Openid':register_client/3, 'Elixir.Boruta.Openid':parse_registration_params/2. This issue affects boruta from 2.3.0 before 2.3.7.

Join the discussion
CVE-2026-63071: CWE-653 Improper Isolation or Compartmentalization in Apache Software Foundation Apache SyncopeCVE-2026-63071
0

Apache Syncope contains an improper isolation vulnerability allowing an administrator with Implementation entitlements to create malicious Groovy classes that bypass the Groovy security sandbox. This affects versions from 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1. The issue is fixed in versions 4.0.7 and 4.1.2 by tightening the Groovy sandbox.

Join the discussion
CVE-2026-53421: CWE-653 Improper Isolation or Compartmentalization in Apache Software Foundation Apache SyncopeCVE-2026-53421
0

Apache Syncope versions from 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1 contain an improper isolation vulnerability. This flaw allows an administrator with sufficient entitlements to achieve remote code execution via the connector subsystem by exploiting Groovy script execution in scripted connectors. The issue is resolved in versions 4.0.7 and 4.1.2 by hardening the Groovy security sandbox.

Join the discussion
CVE-2026-53405: CWE-653 Improper Isolation or Compartmentalization in Apache Software Foundation Apache SyncopeCVE-2026-53405
0

Apache Syncope versions from 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1 contain an improper isolation vulnerability. An administrator with sufficient privileges can import BPMN process definitions containing Groovy scriptTasks via the REST API, which execute without sandboxing on the server. This allows arbitrary Groovy code execution with high impact on confidentiality, integrity, and availability. Versions 4.0.7 and 4.1.2 address this issue by sandboxing Groovy scriptTasks.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: cwe-653
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses