CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
704 vulnerabilities with CWE-668
CVE-2026-41369
MEDIUM
OpenClaw < 2026.3.31 - Insufficient Environment Variable Sanitization in Host Execution
CVSS 6.5
CVE-2026-41368
MEDIUM
OpenClaw < 2026.3.28 - Environment Variable Disclosure via jq $ENV Filter Bypass
CVSS 6.5
CVE-2026-41362
MEDIUM
OpenClaw 2026.2.19 < 2026.3.31 - Webhook Replay Dedupe Cache Event Suppression via Shared Authentication
CVSS 4.3
CVE-2026-6830
LOW
Nesquena Hermes WebUI Environment Variable Credential Leakage via Profile Switch
CVSS 3.3
CVE-2026-32690
LOW
Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1
CVSS 3.7
CVE-2026-30912
HIGH
Apache Airflow: Exposing stack trace in case of constraint error
CVSS 7.5
CVE-2026-35658
MEDIUM
OpenClaw < 2026.3.2 - Filesystem Boundary Bypass in Image Tool
CVSS 6.5
CVE-2026-39911
HIGH
Hashgraph Guardian 3.5.0 Unsandboxed JavaScript Execution RCE
CVSS 8.8
CVE-2026-34538
MEDIUM
Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure)
CVSS 6.5
CVE-2026-34765
MEDIUM
Electron named window.open targets not scoped to the opener's browsing context
CVSS 6.0
CVE-2026-34217
HIGH
SandboxJS has a Sandbox Escape via Prop Object Leak in New Handler
CVSS 7.2
CVE-2026-34780
HIGH
Electron: Context Isolation bypass via contextBridge VideoFrame transfer
CVSS 8.3
CVE-2026-20160
CRITICAL
Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability
CVSS 9.8
CVE-2026-33573
HIGH
OpenClaw < 2026.3.11 - Workspace Boundary Bypass via Agent RPC Parameters
CVSS 8.8
CVE-2026-28779
HIGH
Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications
CVSS 7.5
CVE-2026-28806
CRITICAL
nerves-hub nerves_hub_web - Privilege Escalation
CVE-2026-29093
HIGH
WWBN AVideo <24.0 - Session Hijacking
CVSS 8.1
CVE-2026-2297
MEDIUM
CPython - Info Disclosure
CVE-2026-27466
HIGH
BigBlueButton <=3.0.21 - DoS
CVSS 7.2
CVE-2026-26057
MEDIUM
Skill Scanner API Server - DoS/File Upload
CVSS 6.5
CVE-2026-21528
MEDIUM
Microsoft Azure Iot Explorer < 0.15.13 - Exposure to Wrong Actor
CVSS 6.5
CVE-2026-25643
CRITICAL
Frigate <0.16.4 - RCE
CVSS 9.1
CVE-2026-25725
CRITICAL
Claude Code <2.1.2 - Info Disclosure
CVSS 10.0
CVE-2026-24473
MEDIUM
Hono <4.11.7 - Info Disclosure
CVSS 5.3
CVE-2026-23763
HIGH
VB-Audio Matrix <2.0.2.2 - Privilege Escalation
Details
Vulnerabilities
704