CWE-441
CVEs classified under CWE-441, newest first.
72 CVEsRSS
CVE-2026-87502Medium· 4.2Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page
Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security se…
CVE-2026-28614High· 7.8In onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy
In onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed …
CVE-2026-28607High· 7.8In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy
In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…
CVE-2026-28603High· 7.8In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible read/write access to private files due to a confused deputy
In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible read/write access to private files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges…
CVE-2026-28600High· 7.8In onCreate of PaymentDefaultDialog.java, there is a possible way to change default payment app due to a confused deputy
In onCreate of PaymentDefaultDialog.java, there is a possible way to change default payment app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i…
CVE-2026-28657High· 7.8In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible unauthorized URI permission grant due to a confused deputy
In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible unauthorized URI permission grant due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
CVE-2026-28644High· 7.8In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy
In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User intera…
CVE-2026-28636High· 7.8In setupLayout of PickActivity.java, there is a possible bypass of the "Install unknown apps" security restriction due to a confused deputy
In setupLayout of PickActivity.java, there is a possible bypass of the "Install unknown apps" security restriction due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed.…
CVE-2026-28624High· 7.8In multiple locations, there is a possible read/write access to files without the proper permissions due to a confused deputy
In multiple locations, there is a possible read/write access to files without the proper permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interact…
CVE-2026-28616High· 7.8In Setup Wizard, there is a possible way to force connection to a malicious network due to confused deputy
In Setup Wizard, there is a possible way to force connection to a malicious network due to confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f…
CVE-2026-45520High· 7.8In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy
In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need…
CVE-2026-45519Low· 3.3In screenArgsForPermissionCheckIfAny of multiple locations there is a possible risk of unauthorized access due to a confused deputy
In screenArgsForPermissionCheckIfAny of multiple locations there is a possible risk of unauthorized access due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User int…
CVE-2026-69531Medium· 5.5Unintended proxy or intermediary ('confused deputy') in Microsoft Windows Speech allows an authorized attacker to perform tampering locally.
Unintended proxy or intermediary ('confused deputy') in Microsoft Windows Speech allows an authorized attacker to perform tampering locally.
CVE-2026-86600High· 8.2In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint
In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify …
CVE-2026-86115Medium· 5.0Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens
Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens. Authenticated workflow authors can bypass external URL…
CVE-2026-77348High· 8.2Wallos is an open-source, self-hostable personal subscription tracker
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php by disabling …
CVE-2026-78682High· 7.5nltk: NLTK: Server-Side Request Forgery via HTTP Proxy Configuration (CVE-2026-78682)
A flaw was found in NLTK. When an HTTP proxy is configured, a server-side request forgery (SSRF) vulnerability exists in the `nltk.pathsec.urlopen` function. An attacker can exploit this by providing a seemingly valid public URL, which the…
CVE-2026-63643MediumMagicMirror² is an open source modular smart mirror platform
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/calendar/node_helper.js accepts an attacker-controlled URL, authentication data, and selfSignedCert setting through…
CVE-2026-73424Medium· 6.5Astro is a web framework for content-driven websites
Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/integrations/vercel/src/serverless/entrypoint.ts accepts x_astro_path for the public /_isr function based only on the x-…
CVE-2026-73266High· 7.1A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE)
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a Mana…
CVE-2026-73079High· 8.5Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions
Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider…
CVE-2026-54663Medium· 6.1swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
CVE-2026-43910High· 8.2java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
CVE-2026-17107High· 8.5A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE)
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests wit…
CVE-2026-13062Medium· 6.5MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters
An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the m…
CVE-2026-16158High· 8.7Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source pairs can therefore pr…
CVE-2026-53514High· 7.7Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
CVE-2026-53513Critical· 9.6@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
CVE-2026-55430Medium· 5.8Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
CVE-2026-49821High· 7.7Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration
Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration