CWE-520: .NET Misconfiguration: Use of Impersonation
Allowing a .NET application to run at potentially escalated levels of access to the underlying operating and file systems can be dangerous and result in various forms of attacks.
4 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2019-25608 — Iperius Backup 6.1.0 Privilege Escalation via Backup Job
- CVE-2026-13444 — Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
- CVE-2026-2450 — .NET misconfiguration: use of impersonation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows
- CVE-2026-13442 — Langflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthenticated and insufficiently authorized API endpoints
Recently published
- CVE-2026-13444 — Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
- CVE-2026-13442 — Langflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthenticated and insufficiently authorized API endpoints
- CVE-2026-2450 — .NET misconfiguration: use of impersonation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows
- CVE-2019-25608 — Iperius Backup 6.1.0 Privilege Escalation via Backup Job