CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
719 vulnerabilities with CWE-668
CVE-2026-53826
MEDIUM
OpenClaw < 2026.4.26 - Information Disclosure via Sandboxed Session Spawn
CVSS 4.3
CVE-2026-47141
MEDIUM
vm2: NodeVM observability builtins leak host process and HTTP request data
CVE-2026-48096
MEDIUM
OpenFGA: Cache-key delimiter injection in openfga/openfga shared-iterator and v2 iterator caches enables intra-store authorization-decision poisoning
CVSS 5.0
CVE-2026-42535
CRITICAL
Apache HTTP Server: mod_dav_fs protected directory access
CVSS 9.1
CVE-2026-46430
MEDIUM
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS
CVSS 4.3
CVE-2026-8958
HIGH
Information disclosure, sandbox escape in the Security: Process Sandboxing component
CVSS 8.6
CVE-2026-46723
MEDIUM
Information Disclosure in extension "Faceted Search" (ke_search)
CVE-2026-44552
HIGH
Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
CVSS 8.7
CVE-2026-45411
CRITICAL
vm2: Sandbox Breakout Using Async Generator
CVSS 9.8
CVE-2026-44009
CRITICAL
vm2: Sandbox Breakout Through Null Proto Exception
CVSS 9.8
CVE-2026-44008
CRITICAL
vm2: Snabox breakout via `neutralizeArraySpeciesBatch`
CVSS 9.8
CVE-2026-42875
MEDIUM
External Secrets Operator: Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore
CVE-2026-34095
MEDIUM
action=raw with Special:Mypage subpage title responds with "Content-Type: text/html" on ctype=text/javascript request
CVSS 6.1
CVE-2026-34094
LOW
Customized help link for page protection indicator is relative to subpage name, because the link target is missing the "/wiki/" prefix
CVSS 3.8
CVE-2026-44338
HIGH
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
CVSS 7.3
CVE-2026-41369
MEDIUM
OpenClaw < 2026.3.31 - Insufficient Environment Variable Sanitization in Host Execution
CVSS 6.5
CVE-2026-41368
MEDIUM
OpenClaw < 2026.3.28 - Environment Variable Disclosure via jq $ENV Filter Bypass
CVSS 6.5
CVE-2026-41362
MEDIUM
OpenClaw 2026.2.19 < 2026.3.31 - Webhook Replay Dedupe Cache Event Suppression via Shared Authentication
CVSS 4.3
CVE-2026-6830
LOW
Nesquena Hermes WebUI Environment Variable Credential Leakage via Profile Switch
CVSS 3.3
CVE-2026-32690
LOW
Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1
CVSS 3.7
CVE-2026-30912
HIGH
Apache Airflow: Exposing stack trace in case of constraint error
CVSS 7.5
CVE-2026-35658
MEDIUM
OpenClaw < 2026.3.2 - Filesystem Boundary Bypass in Image Tool
CVSS 6.5
CVE-2026-39911
HIGH
Hashgraph Guardian 3.5.0 Unsandboxed JavaScript Execution RCE
CVSS 8.8
CVE-2026-34538
MEDIUM
Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure)
CVSS 6.5
CVE-2026-34765
MEDIUM
Electron named window.open targets not scoped to the opener's browsing context
CVSS 6.0
Details
Vulnerabilities
719