CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

184 vulnerabilities with CWE-359
CVE-2026-26237 HIGH
QNAP QuMagie < 2.9.0 - Missing Authorization
CVSS 7.5
CVE-2026-25699 MEDIUM
Apache Answer: Authorization Bypass in Timeline API
CVSS 6.1
CVE-2026-8990 MEDIUM
Authentication Bypass in Kidsview
CVE-2026-28963 MEDIUM
iOS and iPadOS < 26.5 - Unauthorized Access to Sensitive User Data via Visual Intelligence
CVSS 4.6
CVE-2026-28906 HIGH
iOS and iPadOS < 18.7.9 - Unauthorized IP Address Tracking via State Management
CVSS 7.5
CVE-2026-7382 MEDIUM
Information Disclosure in MeWare Software's PDKS
CVSS 6.5
CVE-2026-41182 MEDIUM
LangSmith SDK: Streaming token events bypass output redaction
CVSS 5.3
CVE-2026-28950 MEDIUM
iOS/iPadOS <15.8.8/<16.7.16/<17.7.11/<18.7.8/<26.4.2 - Private Data Exposure via Logging
CVSS 6.2
CVE-2026-6765 MEDIUM
Information disclosure in the Form Autofill component
CVSS 5.3
CVE-2026-34226 HIGH
Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies
CVSS 7.5
CVE-2026-3911 LOW
Keycloak - Authenticated Unauthorized User Attribute Exposure via UserResource Endpoint
CVSS 2.7
CVE-2026-0102 LOW
Microsoft Edge Chromium < 145.0.3800.58 - Unauthorized Autofill Data Exposure via Consecutive Taps
CVSS 3.1
CVE-2026-24321 MEDIUM
SAP Commerce Cloud - Info Disclosure
CVSS 5.3
CVE-2026-24735 HIGH
Apache Answer <2.0.0 - Info Disclosure
CVSS 7.5
CVE-2026-20834 MEDIUM
Microsoft Windows Shell - Absolute Path Traversal Spoofing via Physical Attack
CVSS 4.6
CVE-2025-30459 MEDIUM
Apple macOS < 15.4 - Exposure of Private Personal Information to an Unauthorized Actor
CVSS 5.5
CVE-2025-13477 HIGH
OTP Bypass in Digital Operation Services' WifiBurada
CVSS 7.1
CVE-2025-66172 HIGH
Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access to
CVSS 8.1
CVE-2025-66171 MEDIUM
Apache CloudStack: Any user can create a new VM from backups they should not have access to
CVSS 6.5
CVE-2025-15623 HIGH
Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user
CVSS 7.5
CVE-2025-66605 MEDIUM
FAST/TOOLS <10.04 - Info Disclosure
CVSS 5.3
CVE-2025-11598 LOW
mObywatel < 4.71.0 - Unauthorized Personal Information Exposure via App Switcher
CVE-2025-14317 HIGH
Crazy Bubble Tea <915-7.4.1 - Info Disclosure
CVE-2025-3950 LOW
GitLab CE/EE <18.5.5-18.7.1 - Info Disclosure
CVSS 3.5
CVE-2025-68945 MEDIUM
Gitea < 1.21.2 - Unauthenticated Exposure of Private User Projects
CVSS 5.8
Details
Vulnerabilities 184