CWE-942

Permissive Cross-domain Security Policy with Untrusted Domains

Parent: CWE-863 - Incorrect Authorization

The product uses a web-client protection mechanism such as a Content Security Policy (CSP) or cross-domain policy file, but the policy includes untrusted domains with which the web client is allowed to communicate.

114 vulnerabilities with CWE-942
CVE-2026-66005 MEDIUM
Jan Local API Server CORS Origin Reflection via 0.0.0.0 Binding
CVSS 6.3
CVE-2026-15966 HIGH
Improper CORS handling in MOVEit Transfer
CVSS 7.5
CVE-2026-21761 MEDIUM
CORS Misconfiguration in DevOps Loop
CVSS 4.2
CVE-2026-62387 HIGH
Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugin
CVSS 7.1
CVE-2026-61736 CRITICAL
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
CVSS 9.3
CVE-2026-8919 HIGH
Asus GameSDK < V1.0.5 - Permissive Cross-domain Security Policy with Untrusted Domains
CVE-2026-59148 HIGH
Mockoon: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
CVSS 8.8
CVE-2026-59726 CRITICAL
Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
CVSS 10.0
CVE-2026-56458 MEDIUM
HCL DevOps Deploy is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains
CVSS 5.4
CVE-2026-55110 HIGH
Ubiquiti INC UniFi OS Server - Permissive Cross-domain Security Policy with Untrusted Domains
CVSS 7.5
CVE-2026-12084 MEDIUM
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains
CVSS 5.4
CVE-2026-57957 MEDIUM
Papermark 0.22.0 - CORS Misconfiguration in Viewer Upload Endpoint
CVSS 4.7
CVE-2026-54753 MEDIUM
Nx: `nx graph` dev server permissive CORS policy
CVSS 5.9
CVE-2026-46608 HIGH
Glances < 4.5.5 XML-RPC - CORS Origin Wildcard Fallback
CVSS 7.4
CVE-2026-54290 HIGH
Hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
CVSS 7.1
CVE-2026-56076 HIGH
PraisonAI - Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
CVSS 8.1
CVE-2026-50088 HIGH
Aqara Developer Portal cross-origin resource sharing
CVSS 8.2
CVE-2026-50087 HIGH
Aqara IAM/SSO Gateway cross-origin resource sharing
CVSS 8.2
CVE-2026-10056 HIGH
CORS misconfiguration in Nx Witness VMS allows session token exfiltration via cross-origin request
CVSS 7.5
CVE-2026-46685 MEDIUM
RustFS: Reflective CORS with credentials on S3 listener; unauthenticated license metadata endpoint on console
CVE-2026-45021 MEDIUM
Kuma: Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
CVE-2026-9739 CRITICAL
Google Mcp Toolbox For Databases - Permissive Cross-domain Security Policy with Untrusted Domains
CVE-2026-44895 CRITICAL
GitLab MCP Server: SSE transport has no authentication and wildcard CORS, exposing all GitLab tools
CVE-2026-46431 MEDIUM
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *
CVSS 4.3
CVE-2026-8948 CRITICAL
Same-origin policy bypass in the DOM: Networking component
CVSS 9.1
Details
Vulnerabilities 114