CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.

138 vulnerabilities with CWE-915
CVE-2026-12436 HIGH
Improperly Controlled Modification of Dynamically-Determined Object Attributes in GitLab
CVSS 8.4
CVE-2026-63428 MEDIUM
HeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without validating against the form's declared hidden-field set
CVSS 5.8
CVE-2026-63102 MEDIUM
rConfig Core < 8.2.8 Privilege Escalation via Users API role field
CVSS 5.4
CVE-2026-56679 HIGH
9Router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade
CVE-2026-59888 MEDIUM
jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
CVSS 6.5
CVE-2026-58477 HIGH
Sustainable Irrigation Platform 5.2.16 Mass Assignment via HTTP Parameters
CVSS 8.2
CVE-2026-55810 HIGH
Plotly.js Graphing - Critical - PHP object injection - SA-CONTRIB-2026-050
CVSS 8.1
CVE-2026-55809 HIGH
Flag attendance field - Critical - PHP object injection - SA-CONTRIB-2026-049
CVSS 8.1
CVE-2026-55804 MEDIUM
Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
CVSS 5.9
CVE-2026-55803 MEDIUM
Drupal core - Critical - PHP object injection - SA-CORE-2026-005
CVSS 5.9
CVE-2026-15083 MEDIUM
ECA: Event - Condition - Action - Less critical - Information disclosure - SA-CONTRIB-2026-074
CVSS 4.2
CVE-2026-13244 HIGH
Tealium iQ Tag Management - Critical - PHP object injection - SA-CONTRIB-2026-064
CVSS 8.1
CVE-2026-12535 CRITICAL
Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048
CVSS 9.8
CVE-2026-9726 CRITICAL
Drupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code execution - SA-CONTRIB-2026-038
CVSS 9.8
CVE-2026-59721 HIGH
Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection
CVSS 7.2
CVE-2026-54601 MEDIUM
FastGPT < 4.15.0-beta4 - Cross-Tenant Dataset Authorization Bypass
CVSS 6.3
CVE-2026-43925 MEDIUM
FOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized promo code use
CVE-2026-50281 HIGH
Craft CMS: Mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
CVE-2026-50160 CRITICAL
Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite
CVSS 10.0
CVE-2026-55223 MEDIUM
c3p0 exposes a deserialization "sink" via JDBC DataSource bean properties
CVE-2026-54351 HIGH
Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override
CVSS 8.2
CVE-2026-48943 MEDIUM
Joomla Extension - getk2.com - Authenticated user property mass-assignment in K2 extension for Joomla < 2.26
CVSS 6.5
CVE-2026-45687 HIGH
Rocket.Chat: Authenticated Arbitrary Data Export Theft via Mass Assignment in sendFileMessage
CVSS 8.5
CVE-2026-54516 MEDIUM
jackson-databind: Renamed @JsonIgnore'd setters can deserialize via private fields
CVSS 5.3
CVE-2026-54515 MEDIUM
jackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
CVSS 5.3
Details
Vulnerabilities 138