CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

196 vulnerabilities with CWE-359
CVE-2026-55496 MEDIUM
Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicate
CVSS 4.3
CVE-2026-56171 HIGH
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVSS 7.1
CVE-2026-50657 MEDIUM
Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
CVSS 4.7
CVE-2026-62328 HIGH
9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints
CVSS 7.5
CVE-2026-58297 HIGH
Microsoft Edge for Android Information Disclosure Vulnerability
CVSS 7.1
CVE-2026-58296 HIGH
Microsoft Edge for Android Information Disclosure Vulnerability
CVSS 7.1
CVE-2026-57960 MEDIUM
Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_id
CVSS 6.5
CVE-2026-56124 HIGH
phpUploader < 2.0.2 Unauthenticated Database Exposure via index model
CVSS 7.5
CVE-2026-48615 HIGH
Node - Exposure of Private Personal Information to an Unauthorized Actor
CVSS 7.5
CVE-2026-54264 MEDIUM
Angular: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker
CVSS 6.1
CVE-2026-49344 HIGH
Mercator has a Personal Identifiable Information Leak from Query Executor feature
CVE-2026-26237 HIGH
QNAP QuMagie < 2.9.0 - Missing Authorization
CVSS 7.5
CVE-2026-25699 MEDIUM
Apache Answer: Authorization Bypass in Timeline API
CVSS 6.1
CVE-2026-8990 MEDIUM
Authentication Bypass in Kidsview
CVE-2026-28963 MEDIUM
iOS and iPadOS < 26.5 - Unauthorized Access to Sensitive User Data via Visual Intelligence
CVSS 4.6
CVE-2026-28906 HIGH
iOS and iPadOS < 18.7.9 - Unauthorized IP Address Tracking via State Management
CVSS 7.5
CVE-2026-7382 MEDIUM
Information Disclosure in MeWare Software's PDKS
CVSS 6.5
CVE-2026-41182 MEDIUM
LangSmith SDK: Streaming token events bypass output redaction
CVSS 5.3
CVE-2026-28950 MEDIUM
iOS/iPadOS <15.8.8/<16.7.16/<17.7.11/<18.7.8/<26.4.2 - Private Data Exposure via Logging
CVSS 6.2
CVE-2026-6765 MEDIUM
Information disclosure in the Form Autofill component
CVSS 5.3
CVE-2026-34226 HIGH
Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies
CVSS 7.5
CVE-2026-3911 LOW
Keycloak - Authenticated Unauthorized User Attribute Exposure via UserResource Endpoint
CVSS 2.7
CVE-2026-0102 LOW
Microsoft Edge Chromium < 145.0.3800.58 - Unauthorized Autofill Data Exposure via Consecutive Taps
CVSS 3.1
CVE-2026-24321 MEDIUM
SAP Commerce Cloud - Info Disclosure
CVSS 5.3
CVE-2026-24735 HIGH
Apache Answer <2.0.0 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 196