Threats Tagged 'cwe-915'
View all threats tagged with 'cwe-915'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-915'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-17598: CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Sonatype Nexus Repository 3CVE-2026-17598 0 Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least one scheduled task type could supply a crafted property value that caused the system to overwrite the configuration of an unrelated, existing task instead of creating a new one. Join the discussion | CVE Database V5 | 08/07/2026, 16:07:42 UTC Added: 08/07/2026, 16:26:45 UTC |
CVE-2026-69258: CWE-639: Authorization Bypass Through User-Controlled Key in FlowiseAI FlowiseCVE-2026-69258 0 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowData objects in packages/server/src/utils/buildChatflow.ts and packages/server/src/utils/index.ts without checking apiOverrideStatus. This allowed unauthenticated attackers to inject arbitrary properties into the flow execution context of any public chatflow, overwrite values such as chatId, sessionId, and chatHistory, and control values resolved through $flow.* template variables consumed by flow nodes. This issue is fixed in version 3.1.3. Join the discussion | CVE Database V5 | 08/04/2026, 15:56:06 UTC Added: 08/04/2026, 16:28:50 UTC |
CVE-2026-56679: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in decolua 9routerCVE-2026-56679 0 CVE-2026-56679 affects decolua 9router versions prior to 0.5.4. The vulnerability allows an authenticated user to modify security-critical settings via the PATCH /api/settings endpoint because the request body is written to persistent settings without a field whitelist. This can disable authentication for the entire application, exposing protected routes to unauthenticated access. The issue is fixed in version 0.5.4. Join the discussion | CVE Database V5 | 07/15/2026, 20:50:30 UTC Added: 07/15/2026, 21:03:18 UTC |
CVE-2026-59888: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FasterXML jackson-databindCVE-2026-59888 0 A vulnerability in FasterXML jackson-databind versions from 2.15.0 up to but not including 2.18.8, 2.21.4, and 3.1.4 allows Java Records using a PropertyNamingStrategy to bypass the @JsonIgnore annotation. This occurs because the ignored component is recorded under its original name before the naming strategy renames the JSON key, enabling assignment to the Record constructor parameter. The issue is fixed starting from versions 2.18.8, 2.21.4, and 3.1.4. Join the discussion | CVE Database V5 | 07/14/2026, 16:44:20 UTC Added: 07/14/2026, 17:19:02 UTC |
CVE-2026-55810: CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Drupal Plotly.js GraphingCVE-2026-55810 0 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2. Join the discussion | CVE Database V5 | 07/10/2026, 21:44:36 UTC Added: 07/10/2026, 22:03:25 UTC |
CVE-2026-55809: CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Drupal Flag attendance fieldCVE-2026-55809 0 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows Object Injection. This issue affects Flag attendance field versions: from 0.0.0 to 1.2. Join the discussion | CVE Database V5 | 07/10/2026, 21:44:35 UTC Added: 07/10/2026, 22:03:25 UTC |
CVE-2026-55804: CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Drupal Drupal coreCVE-2026-55804 0 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. Join the discussion | CVE Database V5 | 07/10/2026, 21:46:39 UTC Added: 07/10/2026, 22:03:25 UTC |
CVE-2026-15083: CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Drupal ECA: Event - Condition - ActionCVE-2026-15083 0 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects ECA: Event - Condition - Action versions: from 0.0.0 to 2.1.20, from 3.0.0 to 3.0.12, from 3.1.0 to 3.1.4. Join the discussion | CVE Database V5 | 07/10/2026, 21:46:33 UTC Added: 07/10/2026, 22:03:24 UTC |
CVE-2026-13244: CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Drupal Tealium iQ Tag ManagementCVE-2026-13244 0 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injection. This issue affects Tealium iQ Tag Management versions: from 0.0.0 to 2.4.0. Join the discussion | CVE Database V5 | 07/10/2026, 21:46:14 UTC Added: 07/10/2026, 22:03:23 UTC |
CVE-2026-12535: CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Drupal Formatter FieldCVE-2026-12535 0 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0. Join the discussion | CVE Database V5 | 07/10/2026, 21:43:40 UTC Added: 07/10/2026, 22:03:21 UTC |
Showing 1 to 10 of 11 results