CWE-942
Permissive Cross-domain Security Policy with Untrusted Domains
The product uses a web-client protection mechanism such as a Content Security Policy (CSP) or cross-domain policy file, but the policy includes untrusted domains with which the web client is allowed to communicate.
114 vulnerabilities with CWE-942
CVE-2026-66005
MEDIUM
Jan Local API Server CORS Origin Reflection via 0.0.0.0 Binding
CVSS 6.3
CVE-2026-15966
HIGH
Improper CORS handling in MOVEit Transfer
CVSS 7.5
CVE-2026-21761
MEDIUM
CORS Misconfiguration in DevOps Loop
CVSS 4.2
CVE-2026-62387
HIGH
Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugin
CVSS 7.1
CVE-2026-61736
CRITICAL
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
CVSS 9.3
CVE-2026-8919
HIGH
Asus GameSDK < V1.0.5 - Permissive Cross-domain Security Policy with Untrusted Domains
CVE-2026-59148
HIGH
Mockoon: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
CVSS 8.8
CVE-2026-59726
CRITICAL
Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
CVSS 10.0
CVE-2026-56458
MEDIUM
HCL DevOps Deploy is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains
CVSS 5.4
CVE-2026-55110
HIGH
Ubiquiti INC UniFi OS Server - Permissive Cross-domain Security Policy with Untrusted Domains
CVSS 7.5
CVE-2026-12084
MEDIUM
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains
CVSS 5.4
CVE-2026-57957
MEDIUM
Papermark 0.22.0 - CORS Misconfiguration in Viewer Upload Endpoint
CVSS 4.7
CVE-2026-54753
MEDIUM
Nx: `nx graph` dev server permissive CORS policy
CVSS 5.9
CVE-2026-46608
HIGH
Glances < 4.5.5 XML-RPC - CORS Origin Wildcard Fallback
CVSS 7.4
CVE-2026-54290
HIGH
Hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
CVSS 7.1
CVE-2026-56076
HIGH
PraisonAI - Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
CVSS 8.1
CVE-2026-50088
HIGH
Aqara Developer Portal cross-origin resource sharing
CVSS 8.2
CVE-2026-50087
HIGH
Aqara IAM/SSO Gateway cross-origin resource sharing
CVSS 8.2
CVE-2026-10056
HIGH
CORS misconfiguration in Nx Witness VMS allows session token exfiltration via cross-origin request
CVSS 7.5
CVE-2026-46685
MEDIUM
RustFS: Reflective CORS with credentials on S3 listener; unauthenticated license metadata endpoint on console
CVE-2026-45021
MEDIUM
Kuma: Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
CVE-2026-9739
CRITICAL
Google Mcp Toolbox For Databases - Permissive Cross-domain Security Policy with Untrusted Domains
CVE-2026-44895
CRITICAL
GitLab MCP Server: SSE transport has no authentication and wildcard CORS, exposing all GitLab tools
CVE-2026-46431
MEDIUM
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *
CVSS 4.3
CVE-2026-8948
CRITICAL
Same-origin policy bypass in the DOM: Networking component
CVSS 9.1
Details
Vulnerabilities
114