CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

719 vulnerabilities with CWE-668
CVE-2026-53826 MEDIUM
OpenClaw < 2026.4.26 - Information Disclosure via Sandboxed Session Spawn
CVSS 4.3
CVE-2026-47141 MEDIUM
vm2: NodeVM observability builtins leak host process and HTTP request data
CVE-2026-48096 MEDIUM
OpenFGA: Cache-key delimiter injection in openfga/openfga shared-iterator and v2 iterator caches enables intra-store authorization-decision poisoning
CVSS 5.0
CVE-2026-42535 CRITICAL
Apache HTTP Server: mod_dav_fs protected directory access
CVSS 9.1
CVE-2026-46430 MEDIUM
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS
CVSS 4.3
CVE-2026-8958 HIGH
Information disclosure, sandbox escape in the Security: Process Sandboxing component
CVSS 8.6
CVE-2026-46723 MEDIUM
Information Disclosure in extension "Faceted Search" (ke_search)
CVE-2026-44552 HIGH
Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
CVSS 8.7
CVE-2026-45411 CRITICAL
vm2: Sandbox Breakout Using Async Generator
CVSS 9.8
CVE-2026-44009 CRITICAL
vm2: Sandbox Breakout Through Null Proto Exception
CVSS 9.8
CVE-2026-44008 CRITICAL
vm2: Snabox breakout via `neutralizeArraySpeciesBatch`
CVSS 9.8
CVE-2026-42875 MEDIUM
External Secrets Operator: Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore
CVE-2026-34095 MEDIUM
action=raw with Special:Mypage subpage title responds with "Content-Type: text/html" on ctype=text/javascript request
CVSS 6.1
CVE-2026-34094 LOW
Customized help link for page protection indicator is relative to subpage name, because the link target is missing the "/wiki/" prefix
CVSS 3.8
CVE-2026-44338 HIGH
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
CVSS 7.3
CVE-2026-41369 MEDIUM
OpenClaw < 2026.3.31 - Insufficient Environment Variable Sanitization in Host Execution
CVSS 6.5
CVE-2026-41368 MEDIUM
OpenClaw < 2026.3.28 - Environment Variable Disclosure via jq $ENV Filter Bypass
CVSS 6.5
CVE-2026-41362 MEDIUM
OpenClaw 2026.2.19 < 2026.3.31 - Webhook Replay Dedupe Cache Event Suppression via Shared Authentication
CVSS 4.3
CVE-2026-6830 LOW
Nesquena Hermes WebUI Environment Variable Credential Leakage via Profile Switch
CVSS 3.3
CVE-2026-32690 LOW
Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1
CVSS 3.7
CVE-2026-30912 HIGH
Apache Airflow: Exposing stack trace in case of constraint error
CVSS 7.5
CVE-2026-35658 MEDIUM
OpenClaw < 2026.3.2 - Filesystem Boundary Bypass in Image Tool
CVSS 6.5
CVE-2026-39911 HIGH
Hashgraph Guardian 3.5.0 Unsandboxed JavaScript Execution RCE
CVSS 8.8
CVE-2026-34538 MEDIUM
Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure)
CVSS 6.5
CVE-2026-34765 MEDIUM
Electron named window.open targets not scoped to the opener's browsing context
CVSS 6.0
Details
Vulnerabilities 719