CWE-668: Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
189 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-20160 — Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability
- CVE-2025-34119 — EasyCafe Server 2.2.14 Remote File Disclosure via Opcode 0x43
- CVE-2025-9074 — Docker Desktop allows unauthenticated access to Docker Engine API from containers
- CVE-2025-3651 — Command Injection in iManage Work Desktop for Mac's Agent Service
- CVE-2024-38368 — Trunk's 'Claim your pod' could be used to obtain un-used pods
- CVE-2026-25643 — Frigate Affected by Authenticated Remote Command Execution (RCE) and Container Escape
- CVE-2025-34064 — OneLogin AD Connector Log S3 Bucket Hijack Leading to Cross-Tenant Data Leakage
- CVE-2025-32428 — Jupyter Remote Desktop Proxy makes TigerVNC accessible via the network and not just via a UNIX socket as intended
- CVE-2024-24985 — Exposure of resource to wrong sphere in some Intel(R) processors with Intel(R) ACTM may allow a privileged user to poten
- CVE-2026-44009 — vm2: Sandbox Breakout Through Null Proto Exception
- CVE-2026-44008 — vm2: Snabox breakout via `neutralizeArraySpeciesBatch`
- CVE-2026-45411 — vm2: Sandbox Breakout Using Async Generator
- CVE-2026-29093 — WWBN AVideo: Unauthenticated PHP session store exposed to host network via published memcached port
- CVE-2024-29905 — DIRAC: Unauthorized users can read proxy contents during generation
- CVE-2026-73843 — OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
- CVE-2026-28806 — Improper authorization in device bulk actions and device update API allows cross-organization device control
- CVE-2026-48499 — Activepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cache
- CVE-2026-25725 — Claude Code Has Sandbox Escape via Persistent Configuration Injection in settings.json
- CVE-2025-61917 — n8n Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner
- CVE-2026-42535 — Apache HTTP Server: mod_dav_fs protected directory access
Recently published
- CVE-2026-85053 — Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute
- CVE-2026-82652 — SiYuan before v3.8.1 Information Disclosure via Publish Access
- CVE-2026-82650 — SiYuan before v3.8.1 Path Traversal via /api/template/render
- CVE-2026-72924 — GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default
- CVE-2026-79068 — Improper resource exposure in StreamsAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentiall
- CVE-2026-79031 — Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site i
- CVE-2026-59308 — Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation
- CVE-2026-73843 — OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
- CVE-2026-72782 — Craft CMS 5.0.0-RC1 before 5.10.6 Environment Variable Leak
- CVE-2026-72764 — n8n before 1.123.67 Module Cache Poisoning via Code Node
- CVE-2026-70606 — Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
- CVE-2026-48499 — Activepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cache
- CVE-2026-67427 — Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
- CVE-2026-54727 — proot-distro has a Container Isolation Bypass via Crafted Restore Archive
- CVE-2026-54497 — view_component: Reused Component Instances Retain Stale Render Context
- CVE-2026-45077 — Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
- CVE-2026-59835 — A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 th
- CVE-2026-53657 — Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
- CVE-2026-53648 — FOSSBilling: Downloadable product files can be overwritten through filename collisions
- CVE-2026-14611 — DeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exposure of resource
More specific weaknesses
- CWE-1282 — Assumed-Immutable Data is Stored in Writable Memory
- CWE-1327 — Binding to an Unrestricted IP Address
- CWE-134 — Use of Externally-Controlled Format String
- CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor
- CWE-374 — Passing Mutable Objects to an Untrusted Method
- CWE-375 — Returning a Mutable Object to an Untrusted Caller
- CWE-377 — Insecure Temporary File
- CWE-402 — Resource Leak
- CWE-427 — Uncontrolled Search Path Element
- CWE-428 — Unquoted Search Path or Element
- CWE-488 — Exposure of Data Element to Wrong Session
- CWE-491 — Object Hijack
- CWE-492 — Use of Inner Class Containing Sensitive Data
- CWE-493 — Critical Public Variable Without Final Modifier
- CWE-498 — Cloneable Class Containing Sensitive Information
- CWE-499 — Serializable Class Containing Sensitive Data
- CWE-524 — Use of Cache Containing Sensitive Information
- CWE-552 — Files or Directories Accessible to External Parties
- CWE-582 — Array Declared Public, Final, and Static
- CWE-583 — finalize() Method Declared Public
- CWE-608 — Struts: Non-private Field in ActionForm Class
- CWE-642 — External Control of Critical State Data
- CWE-767 — Access to Critical Private Variable via Public Method
- CWE-8 — J2EE Misconfiguration: Entity Bean Declared Remote