CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

732 vulnerabilities with CWE-668
CVE-2026-48499 CRITICAL
Activepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cache
CVE-2026-67427 HIGH
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
CVSS 8.6
CVE-2026-54727 HIGH
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
CVSS 8.2
CVE-2026-54497 MEDIUM
view_component: Reused Component Instances Retain Stale Render Context
CVSS 6.8
CVE-2026-14960 CRITICAL
Pegatron Tdelo64.sys < 02-17-2025 - Unauthenticated Arbitrary Hardware I/O Port Read and Write via IOCTL Handlers
CVSS 9.8
CVE-2026-45077 HIGH
Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
CVSS 8.6
CVE-2026-59835 HIGH
Fortinet FortiSandbox - Exposure of Resource to Wrong Sphere
CVSS 8.6
CVE-2026-53657 HIGH
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
CVSS 8.2
CVE-2026-53648 MEDIUM
FOSSBilling: Downloadable product files can be overwritten through filename collisions
CVE-2026-14611 MEDIUM
DeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exposure of resource
CVSS 4.3
CVE-2026-57231 HIGH
Podman: Malformed Image can trick podman run into leaking host environment variables into the container
CVSS 7.5
CVE-2026-56077 MEDIUM
PraisonAI - Information Disclosure via Shared MultiAgentLedger State
CVSS 6.5
CVE-2026-50202 MEDIUM
Steeltoe's static JWKS cache shared across schemes and never invalidated
CVSS 5.9
CVE-2026-53826 MEDIUM
OpenClaw < 2026.4.26 - Information Disclosure via Sandboxed Session Spawn
CVSS 4.3
CVE-2026-47141 MEDIUM
vm2: NodeVM observability builtins leak host process and HTTP request data
CVE-2026-48096 MEDIUM
OpenFGA: Cache-key delimiter injection in openfga/openfga shared-iterator and v2 iterator caches enables intra-store authorization-decision poisoning
CVSS 5.0
CVE-2026-42535 CRITICAL
Apache HTTP Server: mod_dav_fs protected directory access
CVSS 9.1
CVE-2026-46430 MEDIUM
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS
CVSS 4.3
CVE-2026-8958 HIGH
Information disclosure, sandbox escape in the Security: Process Sandboxing component
CVSS 8.6
CVE-2026-46723 MEDIUM
Information Disclosure in extension "Faceted Search" (ke_search)
CVE-2026-44552 HIGH
Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
CVSS 8.7
CVE-2026-45411 CRITICAL
vm2: Sandbox Breakout Using Async Generator
CVSS 9.8
CVE-2026-44009 CRITICAL
vm2: Sandbox Breakout Through Null Proto Exception
CVSS 9.8
CVE-2026-44008 CRITICAL
vm2: Snabox breakout via `neutralizeArraySpeciesBatch`
CVSS 9.8
CVE-2026-42875 MEDIUM
External Secrets Operator: Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore
Details
Vulnerabilities 732