VYPR

CWE-653

Improper Isolation or Compartmentalization

ClassDraft

Description

The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

When a weakness occurs in functionality that is accessible by lower-privileged users, then without strong boundaries, an attack might extend the scope of the damage to higher-privileged users.

Hierarchy (View 1000)

CVEs mapped to this weakness (73)

page 2 of 4
  • CVE-2026-8945HigMay 19, 2026
    risk 0.49cvss 7.5epss 0.00

    Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.

  • CVE-2025-53710HigDec 18, 2025
    risk 0.49cvss 7.5epss 0.00

    Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each other. This issue resulted in bypass of access control due to the presence of a vulnerable endpoint in Foundry Container Service that…

  • CVE-2024-0136HigJan 28, 2025
    risk 0.49cvss 7.6epss 0.01

    NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a…

  • CVE-2024-0135HigJan 28, 2025
    risk 0.49cvss 7.6epss 0.01

    NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges,…

  • CVE-2024-47520HigJan 10, 2025
    risk 0.49cvss 7.6epss 0.00

    A user with advanced report application access rights can perform actions for which they are not authorized

  • CVE-2026-62246HigJul 30, 2026
    risk 0.48cvss 8.5epss 0.00

    Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and…

  • CVE-2026-65635HigJul 30, 2026
    risk 0.47cvss epss 0.00

    Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attackers to register OpenID Connect clients with administrative privileges through the dynamic client registration entry point. Boruta.Openid.register_client/3…

  • CVE-2026-42782HigMay 25, 2026
    risk 0.47cvss 7.2epss 0.01

    Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer. …

  • CVE-2026-5599HigApr 5, 2026
    risk 0.47cvss epss 0.00

    A user with API access and "manage users" permission in any venueless world is able to trigger deletion of user accounts in other worlds.

  • CVE-2025-41688HigJul 31, 2025
    risk 0.47cvss 7.2epss 0.01

    A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the implemented LUA sandbox.

  • CVE-2025-3086HigApr 4, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous users views and possibly cause a denial of service

  • CVE-2024-23683HigJan 19, 2024
    risk 0.46cvss 8.2epss 0.00

    Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code.

  • CVE-2026-57135higJun 18, 2026
    risk 0.45cvss epss

    ## Summary The published npm package `praisonai` exports a TypeScript `SandboxExecutor` with a `network-isolated` mode. The CLI lists that mode as: ```text network-isolated No network access (proxy blocked) ``` The implementation does not create a network namespace, firewall…

  • CVE-2025-57738HigOct 20, 2025
    risk 0.42cvss 7.2epss 0.23

    Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly…

  • CVE-2024-55456MedFeb 3, 2025
    risk 0.42cvss 6.5epss 0.00

    lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell

  • CVE-2024-57723MedJan 23, 2025
    risk 0.42cvss 6.5epss 0.00

    lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over.

  • CVE-2024-57721MedJan 23, 2025
    risk 0.42cvss 6.5epss 0.00

    lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path.

  • CVE-2024-57720MedJan 23, 2025
    risk 0.42cvss 6.5epss 0.00

    lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend.

  • CVE-2024-30388MedApr 12, 2024
    risk 0.42cvss 6.5epss 0.00

    An Improper Isolation or Compartmentalization vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on QFX5000 Series and EX Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). If a specific malformed LACP packet is…

  • CVE-2026-4282HigApr 2, 2026
    risk 0.41cvss 7.4epss 0.00

    A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable…