Threats Tagged 'cwe-915'
View all threats tagged with 'cwe-915'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-915'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-54516: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FasterXML jackson-databindCVE-2026-54516 0 A vulnerability in FasterXML jackson-databind versions from 2.21.0 until 2.21.4 and 3.1.4 allows an attacker to bypass @JsonIgnore on a setter by renaming a property with @JsonProperty on the getter. This leads to direct modification of a private backing field during deserialization. The issue is fixed in version 3.1.4. Join the discussion | CVE Database V5 | 06/23/2026, 20:48:52 UTC Added: 06/23/2026, 21:09:22 UTC |
CVE-2026-54515: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FasterXML jackson-databindCVE-2026-54515 0 A vulnerability in FasterXML jackson-databind versions from 2.8.0 until fixed versions allows ignored properties to become writable again due to improper handling of property exclusions combined with case-insensitivity processing. This issue is identified as CWE-915 and affects the BeanDeserializerBase.createContextual() method. The vulnerability has a medium severity with a CVSS score of 5.3 and is fixed in versions 2.18.9, 2.21.5, and 3.1.4. Join the discussion | CVE Database V5 | 06/23/2026, 20:50:25 UTC Added: 06/23/2026, 21:09:22 UTC |
CVE-2026-55736: CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes in ash-project ashCVE-2026-55736 0 CVE-2026-55736 is a vulnerability in ash-project ash versions from 3.0.0 up to but not including 3.29.3. It allows users to set private action arguments that should only be controlled by trusted server-side code due to incomplete filtering of private arguments in changesets. This can lead to integrity violations or privilege escalation depending on how the private arguments are used by the application. Join the discussion | CVE Database V5 | 06/23/2026, 18:21:13 UTC Added: 06/23/2026, 18:54:13 UTC |
CVE-2026-56142: CWE-915 in JetBrains HubCVE-2026-56142 0 In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible Join the discussion | CVE Database V5 | 06/19/2026, 11:49:41 UTC Added: 06/19/2026, 12:50:12 UTC |
CVE-2026-46517: CWE-94: Improper Control of Generation of Code ('Code Injection') in InternLM lmdeployCVE-2026-46517 0 LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True" enables HF supply-chain RCE without user opt-in. At time of publication, there are no publicly available patches. Join the discussion | CVE Database V5 | 06/09/2026, 23:05:43 UTC Added: 06/09/2026, 23:25:53 UTC |
CVE-2026-46480: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46480 0 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluator create and update mass-assignment allows cross-workspace evaluator takeover. This issue has been patched in version 3.1.2. Join the discussion | CVE Database V5 | 06/08/2026, 15:32:15 UTC Added: 06/08/2026, 15:49:01 UTC |
CVE-2026-46479: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46479 0 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-assignment allows cross-workspace evaluation takeover. This issue has been patched in version 3.1.2. Join the discussion | CVE Database V5 | 06/08/2026, 15:32:03 UTC Added: 06/08/2026, 15:49:01 UTC |
CVE-2026-46478: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46478 0 FlowiseAI Flowise versions prior to 3.1.2 contain a vulnerability where the DatasetRow create and update functionality allows mass-assignment that can lead to cross-workspace row takeover. This issue is classified under CWE-915, indicating improper control of dynamically-determined object attributes. The vulnerability has been fixed in version 3.1.2. Join the discussion | CVE Database V5 | 06/08/2026, 15:31:55 UTC Added: 06/08/2026, 15:49:01 UTC |
CVE-2026-46477: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46477 0 Flowise versions prior to 3.1.2 contain a vulnerability where mass-assignment in dataset creation and update allows cross-workspace dataset takeover. This issue has been addressed in version 3.1.2. The vulnerability involves improperly controlled modification of dynamically-determined object attributes, classified as CWE-915. Join the discussion | CVE Database V5 | 06/08/2026, 15:31:48 UTC Added: 06/08/2026, 15:48:56 UTC |
CVE-2026-46476: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46476 0 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomTemplate create and update mass-assignment allows cross-workspace template takeover. This issue has been patched in version 3.1.2. Join the discussion | CVE Database V5 | 06/08/2026, 15:31:32 UTC Added: 06/08/2026, 15:48:56 UTC |
Showing 1 to 10 of 17 results