CWE-653

Improper Isolation or Compartmentalization

Parent: CWE-657 - Violation of Secure Design Principles

The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

71 vulnerabilities with CWE-653
CVE-2026-4692 CRITICAL
Sandbox escape in the Responsive Design Mode component
CVSS 10.0
CVE-2026-0542 CRITICAL
ServiceNow AI Platform - Unauthenticated Remote Code Execution in Sandbox
CVE-2026-25905 MEDIUM
mcp-run-python - Improper Isolation via Pyodide API Access
CVSS 5.8
CVE-2025-12805 HIGH
Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy
CVSS 8.1
CVE-2025-53710 HIGH
Foundry Container Service - Privilege Escalation
CVSS 7.5
CVE-2025-46215 MEDIUM
Fortinet FortiSandbox <5.0.1 - Info Disclosure
CVSS 5.3
CVE-2025-41116 LOW
Grafana Databricks Datasource Plugin <1.12.0 - Info Disclosure
CVE-2025-3717 LOW
Grafana Snowflake Datasource Plugin <1.14.1 - Info Disclosure
CVE-2025-12695 MEDIUM
DSPy - Arbitrary File Read via PythonInterpreter Sandbox Escape
CVSS 5.9
CVE-2025-57738 HIGH
Apache Syncope 2.1.0-3.0.13 - Authenticated Remote Code Execution via Groovy Class Injection
CVSS 7.2
CVE-2025-34201 HIGH
Vasion Print Virtual Appliance Host - Lateral Movement
CVSS 7.8
CVE-2025-20109 HIGH
Intel(R) Processors - Privilege Escalation
CVSS 7.8
CVE-2025-41688 HIGH
MB connect line mbNET HW1 < 5.1.11 and mbNET/mbNET.rokey < 7.3.0 - Remote Code Execution via LUA Sandbox Escape
CVSS 7.2
CVE-2025-27027 MEDIUM
Radiflow iSAP Smart Collector 1.20-3.02-1 - Authenticated Restricted Shell Bypass via rbash
CVSS 4.1
CVE-2025-6705 MEDIUM
Eclipse Open VSX Registry - Privilege Escalation
CVSS 5.3
CVE-2025-5476 HIGH
Sony XAV-AX8500 Firmware >=2.00.01 <3.02.00 - Unauthenticated Authentication Bypass via ACL-U Links
CVSS 8.8
CVE-2025-4083 CRITICAL
Thunderbird <138 - Sandbox Escape
CVSS 9.1
CVE-2025-3086 HIGH
M-Files Server < 25.3.14549 - Unauthenticated Denial of Service via User Isolation Bypass
CVSS 7.1
CVE-2025-1974 CRITICAL
Kubernetes ingress-nginx - Pod Network Remote Code Execution
CVSS 9.8
CVE-2025-29781 MEDIUM
Bare Metal Operator < 0.8.1 and 0.9.0 - Unauthorized Secret Access via BMCEventSubscription
CVSS 6.5
CVE-2025-26393 MEDIUM
SolarWinds Service Desk - Privilege Escalation
CVSS 5.4
CVE-2025-21590 MEDIUM KEV
Juniper Networks Junos OS <21.2R3-S9, <21.4R3-S10, <22.2R3-S - Priv...
CVSS 4.4
CVE-2025-24986 MEDIUM
Azure PromptFlow Core < 1.17.2 and PromptFlow Tools < 1.6.0 - Unauthenticated Remote Code Execution
CVSS 6.5
CVE-2024-35281 LOW
FortiClientMac <7.4.2 - Code Injection
CVSS 2.5
CVE-2024-55456 MEDIUM
lunasvg 3.0.1 - Segmentation Violation in gray_find_cell
CVSS 6.5
Details
Vulnerabilities 71