CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

704 vulnerabilities with CWE-668
CVE-2026-41369 MEDIUM
OpenClaw < 2026.3.31 - Insufficient Environment Variable Sanitization in Host Execution
CVSS 6.5
CVE-2026-41368 MEDIUM
OpenClaw < 2026.3.28 - Environment Variable Disclosure via jq $ENV Filter Bypass
CVSS 6.5
CVE-2026-41362 MEDIUM
OpenClaw 2026.2.19 < 2026.3.31 - Webhook Replay Dedupe Cache Event Suppression via Shared Authentication
CVSS 4.3
CVE-2026-6830 LOW
Nesquena Hermes WebUI Environment Variable Credential Leakage via Profile Switch
CVSS 3.3
CVE-2026-32690 LOW
Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1
CVSS 3.7
CVE-2026-30912 HIGH
Apache Airflow: Exposing stack trace in case of constraint error
CVSS 7.5
CVE-2026-35658 MEDIUM
OpenClaw < 2026.3.2 - Filesystem Boundary Bypass in Image Tool
CVSS 6.5
CVE-2026-39911 HIGH
Hashgraph Guardian 3.5.0 Unsandboxed JavaScript Execution RCE
CVSS 8.8
CVE-2026-34538 MEDIUM
Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure)
CVSS 6.5
CVE-2026-34765 MEDIUM
Electron named window.open targets not scoped to the opener's browsing context
CVSS 6.0
CVE-2026-34217 HIGH
SandboxJS has a Sandbox Escape via Prop Object Leak in New Handler
CVSS 7.2
CVE-2026-34780 HIGH
Electron: Context Isolation bypass via contextBridge VideoFrame transfer
CVSS 8.3
CVE-2026-20160 CRITICAL
Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability
CVSS 9.8
CVE-2026-33573 HIGH
OpenClaw < 2026.3.11 - Workspace Boundary Bypass via Agent RPC Parameters
CVSS 8.8
CVE-2026-28779 HIGH
Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications
CVSS 7.5
CVE-2026-28806 CRITICAL
nerves-hub nerves_hub_web - Privilege Escalation
CVE-2026-29093 HIGH
WWBN AVideo <24.0 - Session Hijacking
CVSS 8.1
CVE-2026-2297 MEDIUM
CPython - Info Disclosure
CVE-2026-27466 HIGH
BigBlueButton <=3.0.21 - DoS
CVSS 7.2
CVE-2026-26057 MEDIUM
Skill Scanner API Server - DoS/File Upload
CVSS 6.5
CVE-2026-21528 MEDIUM
Microsoft Azure Iot Explorer < 0.15.13 - Exposure to Wrong Actor
CVSS 6.5
CVE-2026-25643 CRITICAL
Frigate <0.16.4 - RCE
CVSS 9.1
CVE-2026-25725 CRITICAL
Claude Code <2.1.2 - Info Disclosure
CVSS 10.0
CVE-2026-24473 MEDIUM
Hono <4.11.7 - Info Disclosure
CVSS 5.3
CVE-2026-23763 HIGH
VB-Audio Matrix <2.0.2.2 - Privilege Escalation
Details
Vulnerabilities 704