CWE-942

Permissive Cross-domain Security Policy with Untrusted Domains

Parent: CWE-863 - Incorrect Authorization

The product uses a web-client protection mechanism such as a Content Security Policy (CSP) or cross-domain policy file, but the policy includes untrusted domains with which the web client is allowed to communicate.

97 vulnerabilities with CWE-942
CVE-2026-50088 HIGH
Aqara Developer Portal cross-origin resource sharing
CVSS 8.2
CVE-2026-50087 HIGH
Aqara IAM/SSO Gateway cross-origin resource sharing
CVSS 8.2
CVE-2026-10056 HIGH
CORS misconfiguration in Nx Witness VMS allows session token exfiltration via cross-origin request
CVSS 7.5
CVE-2026-46685 MEDIUM
RustFS: Reflective CORS with credentials on S3 listener; unauthenticated license metadata endpoint on console
CVE-2026-45021 MEDIUM
Kuma: Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
CVE-2026-9739 CRITICAL
Google Mcp Toolbox For Databases - Permissive Cross-domain Security Policy with Untrusted Domains
CVE-2026-44895 CRITICAL
GitLab MCP Server: SSE transport has no authentication and wildcard CORS, exposing all GitLab tools
CVE-2026-46431 MEDIUM
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *
CVSS 4.3
CVE-2026-8948 CRITICAL
Same-origin policy bypass in the DOM: Networking component
CVSS 9.1
CVE-2026-8576 MEDIUM
Google Chrome < 148.0.7778.168 - Cross-Origin Data Leak via CORS Implementation
CVSS 4.3
CVE-2026-8537 MEDIUM
Google Chrome < 148.0.7778.168 - Cross-Origin Data Leak via ViewTransitions
CVSS 4.3
CVE-2026-44184 HIGH
Cleanuparr: Reflective CORS combined with trusted-network auth allows cross-origin admin API reads
CVSS 8.0
CVE-2026-7643 MEDIUM
ChatGPTNextWeb NextChat API Endpoint Next.js cross-domain policy
CVSS 4.3
CVE-2026-7581 MEDIUM
alexta69 MeTube CORS Policy main.py on_prepare cross-domain policy
CVSS 4.3
CVE-2026-41056 HIGH
AVideos has CORS Origin Reflection with Credentials on Sensitive API Endpoints that Enables Cross-Origin Account Takeover
CVSS 8.1
CVE-2026-34839 MEDIUM
Glances Vulnerable to Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
CVSS 6.5
CVE-2026-6662 HIGH
ericc-ch copilot-api Token Endpoint server.ts cors cross-domain policy
CVSS 7.3
CVE-2026-6143 MEDIUM
farion1231 cc-switch ProxyServer server.rs cross-domain policy
CVSS 6.3
CVE-2026-5302 MEDIUM
Permissive Cross-domain Policy with Untrusted Domains in coolercontrold
CVSS 6.3
CVE-2026-33533 MEDIUM
Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard
CVSS 6.5
CVE-2026-5321 MEDIUM
vanna-ai vanna FastAPI/Flask Server cross-domain policy
CVSS 4.3
CVE-2026-34449 CRITICAL
SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection
CVSS 9.6
CVE-2026-34237 MEDIUM
MCP Java SDK HTTP Transports - Wildcard CORS
CVSS 6.1
CVE-2026-34227 HIGH
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface
CVSS 8.8
CVE-2026-34200 HIGH
Nhost CLI MCP Server: Missing Inbound Authentication on Explicitly Bound Network Port
CVSS 7.5
Details
Vulnerabilities 97