Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-942'

View all threats tagged with 'cwe-942'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-942

Threats Tagged 'cwe-942'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-65310: CWE-306 Missing authentication for critical function in ANDRITZ HIPASE-250CVE-2026-65310
0

ANDRITZ HIPASE-250, in its default configuration, exposes a data and configuration endpoint without any authentication and with permissive CORS settings. This allows an unauthenticated attacker with network access to read live process values and server configuration. The vulnerability is identified as CWE-306 (Missing Authentication for Critical Function) and CWE-942 (Permissive Cross-domain Whitelist).

Join the discussion
CVE-2026-15966: CWE-942 Permissive cross-domain security policy with untrusted domains in Progress MOVEit TransferCVE-2026-15966
0

Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

Join the discussion
CVE-2024-23578: CWE-942 CWE-692: Incomplete Denial of Request to Insecure Resource in HCLSoftware Aftermarket EPCCVE-2024-23578
0

HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).

Join the discussion
CVE-2026-21761: CWE-942: Permissive Cross-Domain Policy with Untrusted Domains in HCLSoftware DevOps LoopCVE-2026-21761
0

HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains.

Join the discussion
CVE-2026-61736: CWE-942: Permissive Cross-domain Policy with Untrusted Domains in HKUDS LightRAGCVE-2026-61736
0

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentials=True in lightrag/api/lightrag_server.py, causing Starlette CORSMiddleware to effectively whitelist every origin for credentialed cross-origin requests. Any malicious website visited by an authenticated LightRAG user can silently make authenticated API requests, exfiltrating documents and knowledge graph data or performing destructive actions such as deleting the document store. This vulnerability is fixed in 1.5.4.

Join the discussion
CVE-2026-8919: CWE-942: Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDKCVE-2026-8919
0

Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application’s local service endpoint. This can result in information disclosure or data tampering, may cause GameSDK to become unavailable, and may also enable access to the victim’s information on other services. Refer to the ' Security Update for ASUS GameSDK  ' section on the ASUS Security Advisory for more information.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: cwe-942
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses