VYPR

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

BaseIncompleteLikelihood: Medium

Description

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-27 · CAPEC-29

CVEs mapped to this weakness (741)

page 36 of 38
  • CVE-2026-59676MedJul 23, 2026
    risk 0.00cvss epss 0.00

    A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10.

  • CVE-2026-65598HigJul 22, 2026
    risk 0.00cvss 7.5epss 0.00

    n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by swapping a directory for a symlink after the path is validated but before the clone runs. This lets an…

  • CVE-2026-16082MedJul 18, 2026
    risk 0.00cvss 5.3epss 0.00

    A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. The manipulation of the argument cwe leads to time-of-check time-of-use. The attack must be carried out locally. The…

  • CVE-2026-54242MedJul 17, 2026
    risk 0.00cvss 4.9epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image proxy's URL validation in src/Imaging/RemoteUrlValidator.php and src/Imaging/GuzzleAdapter.php could be bypassed using DNS rebinding. The remote hostname was…

  • CVE-2026-62212HigJul 17, 2026
    risk 0.00cvss 7.1epss 0.00

    OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could win a timing window between the DNS validation check and use, allowing…

  • CVE-2026-53410HigJul 16, 2026
    risk 0.00cvss 7.0epss 0.00

    A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.

  • CVE-2026-15449MedJul 16, 2026
    risk 0.00cvss epss 0.00

    A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC_GETMACPROP and DLDIOC_SETMACPROP ioctls on /dev/dld. drv_ioc_prop_common() in usr/src/uts/common/io/dld/dld_drv.c copies the dld_ioc_macprop_t ioctl header in…

  • CVE-2026-48344HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does…

  • CVE-2026-57973MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally.

  • CVE-2026-56648HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-56178MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50673HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50658HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.

  • CVE-2026-4018MedJul 14, 2026
    risk 0.00cvss 6.4epss 0.00

    TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGR_AID_TRACE ability, to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.

  • CVE-2026-62189HigJul 13, 2026
    risk 0.00cvss 7.1epss 0.00

    OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy checks and authorization…

  • CVE-2026-56676HigJul 10, 2026
    risk 0.00cvss 7.4epss 0.00

    9Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetching, but open-sse/translator/concerns/image.js performs the later server-side image fetch with a separate DNS resolution. An authenticated attacker with access…

  • CVE-2026-58198MedJul 9, 2026
    risk 0.00cvss 5.5epss 0.00

    ChatterBot is a machine learning, conversational dialog engine for creating chat bots. Prior to 1.2.14, UbuntuCorpusTrainer.extract() uses a predictable home-rooted output directory (~/ubuntu_data/ubuntu_dialogs) with a check-then-create pattern followed by…

  • CVE-2025-58151CriJul 9, 2026
    risk 0.00cvss epss 0.00

    varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF inside the VM involving mapping a buffer prepared by OVMF. Within varstored, there were insufficient compiler barriers, creating TOCTOU issues with data in…

  • CVE-2026-43927MedJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, a race condition in the cart checkout flow allows an authenticated client to apply a promo code beyond its configured maximum uses. By sending concurrent checkout requests before any…

  • CVE-2026-25271HigJul 6, 2026
    risk 0.00cvss 7.8epss 0.00

    Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.