CWE-669

Incorrect Resource Transfer Between Spheres

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

96 vulnerabilities with CWE-669
CVE-2026-12068 HIGH
Avira Password Manager credential disclosure via cross-origin autofill in Firefox
CVSS 7.4
CVE-2026-44917 MEDIUM
Openstack Ironic - Incorrect Resource Transfer Between Spheres
CVSS 4.9
CVE-2026-46447 MEDIUM
OpenStack Ironic through 35.0.x - Boot Script Injection
CVSS 5.8
CVE-2026-48847 LOW
Roundcube Webmail - Incorrect Resource Transfer Between Spheres
CVSS 3.7
CVE-2026-48846 MEDIUM
Roundcube Webmail - Incorrect Resource Transfer Between Spheres
CVSS 6.5
CVE-2026-48845 MEDIUM
Roundcube Webmail - Incorrect Resource Transfer Between Spheres
CVSS 6.5
CVE-2026-48831 HIGH
Wine < 11.0 - Incorrect Resource Transfer Between Spheres
CVE-2026-44599 LOW
Tor < 0.4.9.7 - Incorrect Resource Transfer via Conflux Legs
CVSS 3.7
CVE-2026-42997 HIGH
OpenStack Ironic <26.1.6 - Auth Bypass
CVSS 7.7
CVE-2026-40552 MEDIUM
Remote Code Execution in mpGabinet
CVE-2026-41525 MEDIUM
KDE Dolphin <25.12.3 - Path Traversal
CVSS 6.5
CVE-2026-31431 HIGH KEV
crypto: algif_aead - Revert to operating out-of-place
CVSS 7.8
CVE-2026-41030 MEDIUM
ONLYOFFICE DesktopEditors <9.3.0 - Privilege Escalation
CVSS 6.2
CVE-2026-40228 LOW
systemd 259 - Unauthenticated Terminal Injection via ANSI Escape Sequences
CVSS 2.9
CVE-2026-40225 MEDIUM
systemd <260 - Privilege Escalation
CVSS 6.4
CVE-2026-35545 MEDIUM
Roundcube Webmail < 1.5.15, 1.6.0-1.6.15, 1.7-beta-1.7-rc5 - Information Disclosure via SVG Animate Element Bypass
CVSS 5.3
CVE-2026-35544 MEDIUM
Roundcube Webmail <1.5.14 - CSS Sanitization Bypass
CVSS 5.3
CVE-2026-35543 MEDIUM
Roundcube Webmail < 1.5.14, 1.6.0-1.6.14, 1.7-beta-1.7-rc5 - Information Disclosure via SVG Animate Attribute Bypass
CVSS 5.3
CVE-2026-35542 MEDIUM
Roundcube Webmail <1.5.14, 1.6.0-1.6.14, 1.7-beta-1.7-rc5 - Information Disclosure via Background Attribute Bypass
CVSS 5.3
CVE-2026-35540 MEDIUM
Roundcube Webmail 1.6.0-1.6.13 - Server-Side Request Forgery via CSS Stylesheet Links
CVSS 5.4
CVE-2026-33265 MEDIUM
LibreChat 0.8.1-rc2 - Authenticated JWT Scope Expansion to RAG API
CVSS 6.3
CVE-2026-32772 LOW
GNU inetutils <=2.7 - Info Disclosure
CVSS 3.4
CVE-2026-24708 HIGH
OpenStack Nova <30.2.2 - Memory Corruption
CVSS 8.2
CVE-2026-25253 HIGH
OpenClaw <2026.1.29 - Info Disclosure
CVSS 8.8
CVE-2025-41660 HIGH
CODESYS Control Boot Application Replacement Enables Code Execution
CVSS 8.8
Details
Vulnerabilities 96