Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-669'

View all threats tagged with 'cwe-669'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-669

Threats Tagged 'cwe-669'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-44917: CWE-669 Incorrect Resource Transfer Between Spheres in OpenStack IronicCVE-2026-44917
0

OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.

Join the discussion
CVE-2026-46447: CWE-669 Incorrect Resource Transfer Between Spheres in OpenStack IronicCVE-2026-46447
0

OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.

Join the discussion
CVE-2026-48847: CWE-669 Incorrect Resource Transfer Between Spheres in Roundcube WebmailCVE-2026-48847
0

CVE-2026-48847 is a vulnerability in Roundcube Webmail versions 1.6.0 through 1.6.15 and 1.7.0 that allows an unauthenticated attacker to delete arbitrary files by exploiting session poisoning via redis or memcache. The vulnerability is classified under CWE-669, indicating incorrect resource transfer between spheres. The CVSS score is 3.7, reflecting a low severity impact primarily affecting availability with no confidentiality or integrity impact.

Join the discussion
CVE-2026-48846: CWE-669 Incorrect Resource Transfer Between Spheres in Roundcube WebmailCVE-2026-48846
0

CVE-2026-48846 is a medium severity vulnerability in Roundcube Webmail versions 1.6.0 through 1.6.15 and 1.7.0. It allows bypassing the remote image blocking feature via a crafted CSS var() value in an email message. This bypass may lead to information disclosure or access-control bypass. No official patch or remediation level has been confirmed yet.

Join the discussion
CVE-2026-48845: CWE-669 Incorrect Resource Transfer Between Spheres in Roundcube WebmailCVE-2026-48845
0

In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message.

Join the discussion
CVE-2026-48831: CWE-669 Incorrect Resource Transfer Between Spheres in WineHQ WineCVE-2026-48831
0

Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some configurations, handling of an EXE file causes that file to be blindly executed with the permissions of the invoker. This allows escaping Flatpak and Snap sandboxes, because MIME handlers are not intended for use by code interpreters and loaders. NOTE: some parties feel that this is not a bug to be addressed in Wine, because there is no known solution that avoids a severe loss of usability (Wine could be a binfmt-misc handler, but binfmt-misc does not exist on all platforms supported by Wine).

Join the discussion
CVE-2026-44599: CWE-669 Incorrect Resource Transfer Between Spheres in torproject TorCVE-2026-44599
0

Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.

Join the discussion
CVE-2026-42997: CWE-669 Incorrect Resource Transfer Between Spheres in OpenStack IronicCVE-2026-42997
0

CVE-2026-42997 is a high-severity vulnerability in OpenStack Ironic prior to version 35.0.1. It involves incorrect resource transfer between security domains (CWE-669) during the import process in the idrac component. A user invoking molds can cause authorization credentials—specifically time-limited Keystone tokens or basic credentials configured for molds storage—to be forwarded to a remote endpoint. This token grants access to all OpenStack services authorized for Ironic, potentially exposing sensitive credentials. Fixed versions include 26.1.6, 29.0.

Join the discussion
CVE-2026-40552: CWE-669: Incorrect Resource Transfer Between Spheres in BinSoft mpGabinetCVE-2026-40552
0

mpGabinet is vulnerable to Remote Command Execution. An authorized user with access to the application and direct access to the backend database can achieve system command execution by uploading an attachment and modifying its storage path in the database to reference an attacker-controlled remote network resource. Alternatively, it is possible to use a previously uploaded file and change its reference. When the application processes the attachment, and a user tries to open it, the referenced resource is executed by the system. Critically, this vulnerability can be exploited by any unauthenticated attacker by chaining it with CVE-2026-40550 and CVE-2026-40551, which allows obtaining database access, and logging onto any account. This issue affects mpGabinet version 23.12.19 and below.

Join the discussion
CVE-2026-41525: CWE-669 Incorrect Resource Transfer Between Spheres in KDE DolphinCVE-2026-41525
0

KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of the FileManager1 protocol allows the path given to be any type of file, including scripts or executables. (By default, Dolphin will then prompt the user to determine if they want to launch a script or executable; however, the intended behavior is to block the attempted action, not present a consent prompt.)

Join the discussion

Showing 1 to 10 of 30 results

Filters:Tag: cwe-669
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses