CWE-653: Improper Isolation or Compartmentalization
The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.
53 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-1974 — ingress-nginx admission controller RCE escalation
- CVE-2026-0542 — Remote Code Execution in ServiceNow AI Platform
- CVE-2025-34201 — Vasion Print (formerly PrinterLogic) Lack of Network Segmentation Between Docker Instances
- CVE-2026-63071 — Apache Syncope: RCE via Groovy Sandbox bypass
- CVE-2026-53421 — Apache Syncope: Remote Code Execution via Scripted Connector
- CVE-2026-53405 — Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask
- CVE-2025-12805 — Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy
- CVE-2025-20109 — Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authe
- CVE-2025-6705 — A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads o
- CVE-2024-47520 — A user with advanced report application access rights can perform actions for which they are not authorized
- CVE-2024-0136 — NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could le
- CVE-2024-0135 — NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could le
- CVE-2025-53710 — Network boundaries not respected in certain Foundry namespaces.
- CVE-2025-41688 — High Privilege RCE via LUA Sandbox Escape
- CVE-2026-62246 — Kamaji: TenantControlPlane namespace/name collision binds two tenants to the same SQL datastore schema + DB user, breaking per-tenant isolation
- CVE-2026-65635 — Boruta dynamic client registration allows creation of over-privileged OAuth clients
- CVE-2024-23682 — Artemis Java Test Sandbox Class Loading Escape
- CVE-2025-29781 — Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD
- CVE-2025-5476 — Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability
- CVE-2025-3086 — User in anonymous role could create and delete views
Recently published
- CVE-2026-15366 — A control logic defect in a specific built-in webpage of Kids Mode allows users to view local gallery photos directly wi
- CVE-2026-71325 — Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
- CVE-2026-62246 — Kamaji: TenantControlPlane namespace/name collision binds two tenants to the same SQL datastore schema + DB user, breaking per-tenant isolation
- CVE-2026-65635 — Boruta dynamic client registration allows creation of over-privileged OAuth clients
- CVE-2026-53421 — Apache Syncope: Remote Code Execution via Scripted Connector
- CVE-2026-53405 — Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask
- CVE-2026-63071 — Apache Syncope: RCE via Groovy Sandbox bypass
- CVE-2026-15738 — Cross-namespace traffic interception via incorrect route precedence ordering in AWS Load Balancer Controller
- CVE-2026-41155 — GPU DDK - SharedSecMem mapped into all GPU virtual address spaces
- CVE-2026-42782 — Apache Syncope: Post-auth RCE via Groovy static
- CVE-2026-41174 — Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding
- CVE-2026-40968 — Spring gRPC SecurityContext leaks across requests on authorization failure
- CVE-2026-5600 — A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact
- CVE-2026-5599 — API allows deletion of users of other instance
- CVE-2026-34775 — Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
- CVE-2026-4325 — Keycloak: keycloak: replay of action tokens via improper handling of single-use entries
- CVE-2026-4282 — Keycloak: keycloak: privilege escalation via forged authorization codes due to singleuseobjectprovider isolation flaw
- CVE-2025-12805 — Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy
- CVE-2026-0542 — Remote Code Execution in ServiceNow AI Platform
- CVE-2026-25905 — Lack of isolation in mcp-run-python leads to MCP server takeover