CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.

138 vulnerabilities with CWE-915
CVE-2026-45396 MEDIUM
Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation
CVSS 5.4
CVE-2026-45229 HIGH
Quark Drive < 0.8.5 Mass Assignment via POST /update
CVSS 8.8
CVE-2026-31252 MEDIUM
CosyVoice <=6e01309 Remote Code Execution via Insecure Model File Deserialization
CVSS 5.7
CVE-2026-31251 HIGH
CosyVoice thru 6e01309 - Deserialization
CVSS 7.3
CVE-2026-42264 HIGH
Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking
CVSS 7.4
CVE-2026-41139 HIGH
Unsafe array index getter in mathjs
CVSS 8.8
CVE-2026-33453 CRITICAL
Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution
CVSS 10.0
CVE-2026-42044 MEDIUM
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
CVSS 6.5
CVE-2026-42041 MEDIUM
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
CVSS 4.8
CVE-2026-42033 HIGH
Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
CVSS 7.4
CVE-2026-6912 HIGH
AWS Ops Wheel - Authenticated Privilege Escalation via Cognito User Pool UpdateUserAttributes API
CVSS 8.8
CVE-2026-40897 HIGH
mathjs 13.1.1-15.1.9 - Remote Code Execution via Expression Parser
CVSS 8.8
CVE-2026-41043 MEDIUM
Apache ActiveMQ, Apache ActiveMQ Web: ActiveMQ Web Console - XSS vulnerability when browsing queues
CVSS 6.5
CVE-2026-41277 HIGH
Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
CVSS 8.8
CVE-2026-41267 HIGH
Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association
CVSS 8.1
CVE-2026-40569 CRITICAL
FreeScout's Mass Assignment in Mailbox Connection Settings Enables Silent Email Exfiltration
CVSS 9.0
CVE-2026-34427 HIGH
Vvveb < 1.0.8.1 Privilege Escalation via admin/user/save
CVSS 8.8
CVE-2026-40486 MEDIUM
Kimai's User Preferences API allows standard users to modify restricted attributes: hourly_rate, internal_rate
CVSS 4.3
CVE-2026-40175 MEDIUM
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVSS 4.8
CVE-2026-34179 CRITICAL
Update of type field in restricted TLS certificate allows privilege escalation to cluster admin
CVSS 9.1
CVE-2026-5708 HIGH
Improper Control of User-Modifiable Attributes in RES CreateSession API
CVSS 8.8
CVE-2026-34208 CRITICAL
SandboxJS: Sandbox integrity escape
CVSS 10.0
CVE-2026-34445 HIGH
ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
CVSS 8.6
CVE-2026-5251 MEDIUM
z-9527 admin User Update Endpoint user.js dynamically-determined object attributes
CVSS 6.3
CVE-2026-5248 MEDIUM
gougucms User Registration Login.php reg_submit dynamically-determined object attributes
CVSS 6.3
Details
Vulnerabilities 138