CWE-488: Exposure of Data Element to Wrong Session
The product does not sufficiently enforce boundaries between the states of different sessions, causing data to be provided to, or used by, the wrong session.
36 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-47928 — Spotipy repo vulnerable to secrets exfiltration via `pull_request_target`
- CVE-2026-16498 — terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
- CVE-2026-16326 — consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
- CVE-2024-38367 — CoacoaPods trunk sessions verification step could be manipulated for owner session hijacking
- CVE-2024-5148 — Gnome-remote-desktop: inadequate validation of session agents using d-bus methods may expose rdp tls certificate
- CVE-2024-41977 — A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM
- CVE-2024-27935 — Deno's Node.js Compatibility Runtime has Cross-Session Data Contamination
- CVE-2026-86492 — In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tok
- CVE-2025-1247 — Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared instance
- CVE-2026-34391 — Fleet Vulnerable to Windows MDM cross-device command disclosure
- CVE-2026-33215 — NATS is vulnerable to MQTT hijacking via Client ID
- CVE-2026-23646 — OpenProject users can delete other user's session, causing them to be logged out
- CVE-2026-18489 — IBM ContextForge Translate is affected by cross-client credential context confusion
- CVE-2026-23919 — Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Server
- CVE-2025-2312 — cifs.upcall makes an upcall to the wrong namespace in containerized environments
- CVE-2026-54497 — view_component: Reused Component Instances Retain Stale Render Context
- CVE-2026-84685 — Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Management
- CVE-2026-9831 — ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentication Race Condition
- CVE-2026-46416 — Microsoft UFO shared WebSocket handler state causes cross-client response hijacking
- CVE-2025-27606 — Element Android PIN autologout bypass
Recently published
- CVE-2026-84685 — Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Management
- CVE-2026-86492 — In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tok
- CVE-2026-18489 — IBM ContextForge Translate is affected by cross-client credential context confusion
- CVE-2026-82367 — Re-entrant synchronous publish in AshGraphql subscription batcher delivers one subscriber's records to another's topic
- CVE-2026-71850 — Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
- CVE-2026-16326 — consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
- CVE-2026-16498 — terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
- CVE-2026-54497 — view_component: Reused Component Instances Retain Stale Render Context
- CVE-2026-14621 — FederatedAI FATE OSX Broker QueuePushReqStreamObserver.java QueuePushReqStreamObserver.initEggroll wrong session
- CVE-2026-54311 — n8n: Merge Node SQL Mode Prototype Pollution
- CVE-2026-9831 — ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentication Race Condition
- CVE-2026-46416 — Microsoft UFO shared WebSocket handler state causes cross-client response hijacking
- CVE-2026-34391 — Fleet Vulnerable to Windows MDM cross-device command disclosure
- CVE-2026-33215 — NATS is vulnerable to MQTT hijacking via Client ID
- CVE-2026-23919 — Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Server
- CVE-2025-15576 — Jail chroot escape via fd exchange with a different jail
- CVE-2026-23844 — Whisper Money has IDOR Vulnerability on sync/balances endpoint
- CVE-2026-23646 — OpenProject users can delete other user's session, causing them to be logged out
- CVE-2025-24934 — SO_REUSEPORT_LB breaks connect(2) for UDP sockets
- CVE-2025-47928 — Spotipy repo vulnerable to secrets exfiltration via `pull_request_target`