CWE-284
CVEs classified under CWE-284, newest first.
1097 CVEsRSS
CVE-2026-53816High· 7.2OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
GHSA-xww8-gqvh-92x9High· 8.0OpenClaw: Exec approval display truncation could hide the command being approved
OpenClaw: Exec approval display truncation could hide the command being approved
GHSA-qh2f-99mv-mrcfMediumOpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn
OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn
GHSA-2j8v-hwgc-x698HighOpenClaw: Shell wrapper argv could change between approval and execution
OpenClaw: Shell wrapper argv could change between approval and execution
CVE-2026-53812Medium· 7.7OpenClaw's browser act interactions could bypass private-network navigation checks
OpenClaw's browser act interactions could bypass private-network navigation checks
CVE-2026-53810High· 8.8OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
GHSA-rggc-m335-3wvjHighOpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
CVE-2026-53817High· 8.0OpenClaw: Control UI locality spoofing could mint a durable admin device token
OpenClaw: Control UI locality spoofing could mint a durable admin device token
CVE-2026-53814High· 8.4OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority
OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority
GHSA-mhq8-78pj-5j79High· 7.1OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
GHSA-7m8x-qg2j-4m3vHigh· 8.1Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec
Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec
CVE-2026-49822High· 7.7Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance
Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance
CVE-2026-49823High· 7.7Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook
Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook
CVE-2026-49824High· 8.5Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook
Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook
CVE-2026-50545Critical· 9.9Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover
Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover
CVE-2026-50563Critical· 9.9Fission Container Executor Function PodSpec Injection Leading to Node Escape
Fission Container Executor Function PodSpec Injection Leading to Node Escape
CVE-2026-50564Critical· 9.9Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape
Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape
CVE-2026-56290Critical· 9.8CISA KEVPoCThe Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
GHSA-vgrc-hq28-p3xpHigh· 7.4Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF
CVE-2026-53520Medium· 6.5Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing
Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing
CVE-2026-48529Medium· 6.0GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion
GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion
CVE-2026-52810HighPoCGogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
CVE-2024-37155Medium· 6.5OpenCTI May Bypass Introspection Restriction
OpenCTI May Bypass Introspection Restriction
CVE-2026-31978Medium· 6.5motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint
motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint
CVE-2026-50132High· 7.3Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF
Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF
CVE-2026-48939Critical· 9.8CISA KEVPoCA vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
CVE-2026-47647Critical· 9.9Dynamics 365 Elevation of Privilege Vulnerability
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
CVE-2026-53843High· 8.8OpenClaw: Pairing-scoped device session could restore revoked node token authority
OpenClaw: Pairing-scoped device session could restore revoked node token authority
CVE-2026-55670LowZITADEL: Cross-Tenant User Leakage via Recycled Identifiers
ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers
CVE-2026-53855High· 8.1OpenClaw: Shell positional parameters could weaken strict inline-eval checks
OpenClaw: Shell positional parameters could weaken strict inline-eval checks