Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-915'

View all threats tagged with 'cwe-915'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-915

Threats Tagged 'cwe-915'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-54516: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FasterXML jackson-databindCVE-2026-54516
0

A vulnerability in FasterXML jackson-databind versions from 2.21.0 until 2.21.4 and 3.1.4 allows an attacker to bypass @JsonIgnore on a setter by renaming a property with @JsonProperty on the getter. This leads to direct modification of a private backing field during deserialization. The issue is fixed in version 3.1.4.

Join the discussion
CVE-2026-54515: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FasterXML jackson-databindCVE-2026-54515
0

A vulnerability in FasterXML jackson-databind versions from 2.8.0 until fixed versions allows ignored properties to become writable again due to improper handling of property exclusions combined with case-insensitivity processing. This issue is identified as CWE-915 and affects the BeanDeserializerBase.createContextual() method. The vulnerability has a medium severity with a CVSS score of 5.3 and is fixed in versions 2.18.9, 2.21.5, and 3.1.4.

Join the discussion
CVE-2026-55736: CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes in ash-project ashCVE-2026-55736
0

CVE-2026-55736 is a vulnerability in ash-project ash versions from 3.0.0 up to but not including 3.29.3. It allows users to set private action arguments that should only be controlled by trusted server-side code due to incomplete filtering of private arguments in changesets. This can lead to integrity violations or privilege escalation depending on how the private arguments are used by the application.

Join the discussion
CVE-2026-56142: CWE-915 in JetBrains HubCVE-2026-56142
0

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible

Join the discussion
CVE-2026-46517: CWE-94: Improper Control of Generation of Code ('Code Injection') in InternLM lmdeployCVE-2026-46517
0

LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True" enables HF supply-chain RCE without user opt-in. At time of publication, there are no publicly available patches.

Join the discussion
CVE-2026-46480: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46480
0

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluator create and update mass-assignment allows cross-workspace evaluator takeover. This issue has been patched in version 3.1.2.

Join the discussion
CVE-2026-46479: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46479
0

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-assignment allows cross-workspace evaluation takeover. This issue has been patched in version 3.1.2.

Join the discussion
CVE-2026-46478: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46478
0

FlowiseAI Flowise versions prior to 3.1.2 contain a vulnerability where the DatasetRow create and update functionality allows mass-assignment that can lead to cross-workspace row takeover. This issue is classified under CWE-915, indicating improper control of dynamically-determined object attributes. The vulnerability has been fixed in version 3.1.2.

Join the discussion
CVE-2026-46477: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46477
0

Flowise versions prior to 3.1.2 contain a vulnerability where mass-assignment in dataset creation and update allows cross-workspace dataset takeover. This issue has been addressed in version 3.1.2. The vulnerability involves improperly controlled modification of dynamically-determined object attributes, classified as CWE-915.

Join the discussion
CVE-2026-46476: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46476
0

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomTemplate create and update mass-assignment allows cross-workspace template takeover. This issue has been patched in version 3.1.2.

Join the discussion

Showing 1 to 10 of 17 results

Filters:Tag: cwe-915
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses