CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.

138 vulnerabilities with CWE-915
CVE-2026-34406 HIGH
APTRS: Privilege Escalation via Mass Assignment of is_superuser in User Edit Endpoint
CVSS 8.8
CVE-2026-33228 CRITICAL
flatted: Prototype Pollution via parse()
CVSS 9.8
CVE-2026-27953 HIGH
ormar <0.23.1 Model Constructor - Pydantic Validation Bypass
CVSS 7.1
CVE-2026-32742 MEDIUM
Parse Server session creation endpoint allows overwriting server-generated session fields
CVSS 4.3
CVE-2026-29056 HIGH
Kanboard's privilege escalation via mass assignment in user invite registration allows any invited user to become admin
CVSS 8.8
CVE-2026-21886 MEDIUM
OpenCTI's GraphQL Mutations Allow Deletion of Unrelated Entities
CVSS 6.5
CVE-2026-32640 CRITICAL
(SimpleEval) Objects (including modules) can leak dangerous modules through to direct access inside the sandbox.
CVSS 9.8
CVE-2026-27591 CRITICAL
Winter CMS <1.0.477/1.1.12/1.2.12 - Privilege Escalation
CVSS 9.9
CVE-2026-31815 MEDIUM
django-unicorn <0.67.0 - Auth Bypass
CVSS 5.3
CVE-2026-30822 HIGH
Flowise < 3.0.13 - Unauthenticated Arbitrary Database Field Injection via Lead Creation
CVSS 7.7
CVE-2026-29063 CRITICAL
Immutable.js <3.8.3/4.3.7/5.1.5 - Prototype Pollution
CVSS 9.8
CVE-2026-28781 MEDIUM
Craft CMS <4.17.0-beta.1/5.9.0-beta.1 - Privilege Escalation
CVSS 6.5
CVE-2026-28219 MEDIUM
Discourse <2025.12.2/2026.1.1/2026.2.0 - Privilege Escalation
CVSS 4.3
CVE-2026-27125 MEDIUM
svelte < 5.51.5 - Prototype Pollution in Server-Side Rendering Attribute Spreading
CVSS 6.8
CVE-2026-25521 HIGH
locutus 2.0.12-2.0.38 - Prototype Pollution via String.prototype
CVSS 8.8
CVE-2026-24140 LOW
MyTube < 1.7.78 - Mass Assignment via Settings Management
CVSS 2.7
CVE-2026-23522 LOW
LobeChat <2.0.0-next.193 - Privilege Escalation
CVSS 3.7
CVE-2026-22814 HIGH
@adonisjs/lucid <22.0.0-next.6 - SQL Injection
CVE-2026-22783 CRITICAL
Iris <2.4.24 - Privilege Escalation
CVSS 9.6
CVE-2026-21695 MEDIUM
Titra < 0.99.50 - Authenticated Mass Assignment via Customfields Parameter
CVSS 4.3
CVE-2025-69691 CRITICAL
Netgate pfSense CE 2.8.0 - Code Injection
CVSS 9.9
CVE-2025-69690 CRITICAL
Netgate pfSense CE 2.7.2 - Code Injection
CVSS 9.1
CVE-2025-14341 HIGH
Input Data Manipulation in DivvyDrive Information Technologies' DivvyDrive
CVSS 8.3
CVE-2025-15602 HIGH
Snipe-IT <8.3.7 - Privilege Escalation
CVSS 8.8
CVE-2025-61781 HIGH
OpenCTI < 6.8.1 - Unauthenticated Authorization Bypass via WorkspacePopoverDeletionMutation
CVSS 7.1
Details
Vulnerabilities 138