CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes
The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
137 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-68109 — ChurchCRM vulnerable to RCE with database restore functionality
- CVE-2026-27591 — Winter: Privilege escalation by authenticated backend users
- CVE-2025-58367 — DeepDiff is vulnerable to DoS and Remote Code Execution via Delta class pollution
- CVE-2024-5452 — RCE via Property/Class Pollution in lightning-ai/pytorch-lightning
- CVE-2026-22783 — Iris Allows Arbitrary File Deletion via Mass Assignment in Datastore File Management
- CVE-2026-12436 — Improperly Controlled Modification of Dynamically-Determined Object Attributes in GitLab
- CVE-2026-34406 — APTRS: Privilege Escalation via Mass Assignment of is_superuser in User Edit Endpoint
- CVE-2025-2304 — Camaleon CMS Privilege Escalation
- CVE-2025-24370 — Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
- CVE-2024-0404 — Mass Assignment Vulnerability in mintplex-labs/anything-llm
- CVE-2026-50160 — Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite
- CVE-2026-34208 — SandboxJS: Sandbox integrity escape
- CVE-2026-22814 — Mass Assignment in AdonisJS Lucid Allows Overwriting Internal ORM State
- CVE-2026-9726 — Drupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code execution - SA-CONTRIB-2026-038
- CVE-2026-12535 — Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048
- CVE-2025-30358 — Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
- CVE-2026-56142 — In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privileg
- CVE-2026-45058 — electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark
- CVE-2026-30822 — Flowise: Mass Assignment in `/api/v1/leads` Endpoint
- CVE-2025-52656 — HCL MyXalytics product is affected by Mass Assignment vulnerability
Recently published
- CVE-2026-85408 — Eleveo Quality Management Conversation events dynamically-determined object attributes
- CVE-2026-84430 — gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes
- CVE-2026-83557 — jackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator's unsafe base types
- CVE-2026-78038 — Job argument injection via :args overrides primary_key and tenant in AshOban
- CVE-2026-77144 — Broken Access Control in extension "Events 2" (events2)
- CVE-2026-71504 — Dolibarr < 24.0.0 Members REST API Improper Authorization via Password Reset
- CVE-2026-78416 — Authenticated RCE via `condition.config` JSON cleanse bypass
- CVE-2026-62315 — Frappe: Mass assignment via set_value
- CVE-2026-49428 — posixshm: system calls can incorrectly free memory of largepage objects
- CVE-2026-53958 — 4gaBoards: SSO Pre-Account Takeover / Hijacking via Mass Assignment
- CVE-2026-72655 — Improperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana Leading to Unauthorized Data Modification
- CVE-2026-71473 — Acm-search-v2-rhel9: search-v2-operator: addonfactory.getvaluesfromaddonannotation enables arbitrary helm-values override per spoke
- CVE-2026-17095 — IBM i is Affected By Multiple Vulnerabilities in Navigator for i
- CVE-2026-72778 — Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config
- CVE-2026-18617 — Data-science-pipelines-operator: dspo: mysql dsn parameter injection via customextraparams enables local infile file exfiltration from operator pod
- CVE-2026-72719 — Chatwoot: Cross-Account Resource Transfer via `account_id` Parameter
- CVE-2026-17598 — Nexus Repository 3 - Improper Input Validation in Scheduled Task Configuration
- CVE-2026-69258 — Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
- CVE-2026-12436 — Improperly Controlled Modification of Dynamically-Determined Object Attributes in GitLab
- CVE-2026-63428 — HeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without validating against the form's declared hidden-field set
More specific weaknesses
- CWE-1321 — Prototype Pollution