Skip to main content

Threats Tagged 'cwe-653'

View all threats tagged with 'cwe-653'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-653

Threats Tagged 'cwe-653'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-102125 is a high-severity vulnerability in Kiteworks Core where the sandbox isolating document conversion does not fully confine code execution. This allows code running inside the sandbox to escape confinement and operate with the privileges of the service account running the application. Exploitation could enable an attacker to read or modify application data and configuration or disrupt the service on the affected appliance.

Join the discussion

A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.7-rc.2. Affected is an unknown function of the file packages/sandbox/sandbox-local/src/profiles.ts of the component Landlock Backend. Such manipulation leads to improper isolation or compartmentalization. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. It is advisable to implement a patch to correct this issue. The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion

Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device activation.

Join the discussion

CVE-2026-82964 is a high-severity vulnerability in Gen Digital's Avast security products affecting versions prior to 26.8. It involves improper preservation of permissions in the Avast sandbox minifilter driver on Windows, allowing a local low-privileged attacker inside the sandbox to escape file isolation and escalate privileges to SYSTEM. The flaw arises because the driver fails to correctly apply the original security descriptor when virtualizing files, resulting in permissive permissions on virtualized copies. This enables a sandboxed process to rewrite security descriptors, access sensitive files like the SAM database, extract NTLM password hashes, and execute code with SYSTEM privileges.

Join the discussion

PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment variables and does not establish an operating-system network boundary. Programs that ignore those proxy variables can open sockets directly, allowing supposedly isolated commands to reach localhost, internal services, cloud metadata, or external hosts and potentially exfiltrate data. An initial remediation was released in version 1.7.2.

Join the discussion

CVE-2026-15366 is a low-severity vulnerability in vivo's Kids Mode feature. It involves a control logic defect in a built-in webpage that allows users to view local gallery photos directly within the page, indicating improper isolation or compartmentalization. No patch or official remediation has been announced yet.

Join the discussion

Kamaji, a Hosted Control Plane Manager for Kubernetes, has an improper access control vulnerability prior to version 26.7.4-edge. The issue arises from a lossy normalization process that causes distinct tenants with colliding normalized identifiers to share control-plane state. This allows unauthorized tenants to read, modify, or destroy another tenant's Kubernetes data. The vulnerability is identified as CVE-2026-62246 and has a high severity score of 8.5. The problem is fixed in version 26.7.4-edge.

Join the discussion

Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attackers to register OpenID Connect clients with administrative privileges through the dynamic client registration entry point. Boruta.Openid.register_client/3 forwards caller-supplied registration parameters to the administrative client creation path without a public/admin field-level allowlist, so an unauthenticated registrant can set security-sensitive attributes including supported grant types, authorized scopes, PKCE enforcement, public refresh and revocation behavior, token lifetimes, and signing settings. The library does not distinguish between metadata a public registrant is allowed to set and administrative controls that should require operator approval. This vulnerability is associated with program files lib/boruta/openid.ex and program routines 'Elixir.Boruta.Openid':register_client/3, 'Elixir.Boruta.Openid':parse_registration_params/2. This issue affects boruta from 2.3.0 before 2.3.7.

Join the discussion

Apache Syncope versions from 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1 contain an improper isolation vulnerability. This flaw allows an administrator with sufficient entitlements to achieve remote code execution via the connector subsystem by exploiting Groovy script execution in scripted connectors. The issue is resolved in versions 4.0.7 and 4.1.2 by hardening the Groovy security sandbox.

Join the discussion

Apache Syncope versions from 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1 contain an improper isolation vulnerability. An administrator with sufficient privileges can import BPMN process definitions containing Groovy scriptTasks via the REST API, which execute without sandboxing on the server. This allows arbitrary Groovy code execution with high impact on confidentiality, integrity, and availability. Versions 4.0.7 and 4.1.2 address this issue by sandboxing Groovy scriptTasks.

Join the discussion

Showing 1 to 10 of 32 results

Filters:Tag: cwe-653
Page 1 of 4
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses