CWE-653

Improper Isolation or Compartmentalization

Parent: CWE-657 - Violation of Secure Design Principles

The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

71 vulnerabilities with CWE-653
CVE-2026-62246 HIGH
Kamaji: TenantControlPlane namespace/name collision binds two tenants to the same SQL datastore schema + DB user, breaking per-tenant isolation
CVSS 8.5
CVE-2026-65635 HIGH
Boruta dynamic client registration allows creation of over-privileged OAuth clients
CVE-2026-63071 CRITICAL
Apache Syncope: RCE via Groovy Sandbox bypass
CVSS 9.8
CVE-2026-53421 CRITICAL
Apache Syncope: Remote Code Execution via Scripted Connector
CVSS 9.8
CVE-2026-53405 CRITICAL
Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask
CVSS 9.8
CVE-2026-15738 HIGH
Cross-namespace traffic interception via incorrect route precedence ordering in AWS Load Balancer Controller
CVSS 8.5
CVE-2026-12297 CRITICAL
Sandbox escape due to incorrect boundary conditions in the Networking component
CVSS 9.6
CVE-2026-12295 CRITICAL
Sandbox escape in the DOM: Navigation component
CVSS 9.6
CVE-2026-41155 MEDIUM
GPU DDK - SharedSecMem mapped into all GPU virtual address spaces
CVSS 5.5
CVE-2026-42782 HIGH
Apache Syncope: Post-auth RCE via Groovy static
CVSS 7.2
CVE-2026-8945 HIGH
Sandbox escape in Firefox and Firefox Focus for Android
CVSS 7.5
CVE-2026-44009 CRITICAL
vm2: Sandbox Breakout Through Null Proto Exception
CVSS 9.8
CVE-2026-44005 CRITICAL
vm2: Sandbox escape
CVSS 10.0
CVE-2026-43997 CRITICAL
vm2: Sandbox Escape
CVSS 10.0
CVE-2026-8401 CRITICAL
Firefox < 150.0.3 - Sandbox Escape via Profile Backup Component
CVSS 9.8
CVE-2026-26956 CRITICAL
vm2: WASM Sandbox Escape (Node 25 only)
CVSS 9.8
CVE-2026-26332 CRITICAL
vm2: Sandbox Escape
CVSS 9.8
CVE-2026-24781 CRITICAL
vm2: Sandbox Breakout Through Inspect
CVSS 9.8
CVE-2026-41174 MEDIUM
Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding
CVSS 6.4
CVE-2026-40968 MEDIUM
Spring gRPC SecurityContext leaks across requests on authorization failure
CVSS 4.2
CVE-2026-5600 MEDIUM
pretix 2025.10.0-2026.1.1, 2026.2.0, 2026.3.0 - Unauthorized Data Access via Check-In Events API Endpoint
CVSS 4.3
CVE-2026-5599 HIGH
API allows deletion of users of other instance
CVE-2026-34775 MEDIUM
Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
CVSS 6.8
CVE-2026-4325 MEDIUM
Keycloak: keycloak: replay of action tokens via improper handling of single-use entries
CVSS 5.3
CVE-2026-4282 HIGH
Keycloak: keycloak: privilege escalation via forged authorization codes due to singleuseobjectprovider isolation flaw
CVSS 7.4
Details
Vulnerabilities 71