CWE-653
Improper Isolation or Compartmentalization
Description
The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.
Hierarchy (View 1000)
CVEs mapped to this weakness (73)
page 2 of 4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-8945 | Hig | 0.49 | 7.5 | 0.00 | May 19, 2026 | Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151. | ||
| CVE-2025-53710 | Hig | 0.49 | 7.5 | 0.00 | Dec 18, 2025 | Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each other. This issue resulted in bypass of access control due to the presence of a vulnerable endpoint in Foundry Container Service that… | ||
| CVE-2024-0136 | Hig | 0.49 | 7.6 | 0.01 | Jan 28, 2025 | NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a… | ||
| CVE-2024-0135 | Hig | 0.49 | 7.6 | 0.01 | Jan 28, 2025 | NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges,… | ||
| CVE-2024-47520 | Hig | 0.49 | 7.6 | 0.00 | Jan 10, 2025 | A user with advanced report application access rights can perform actions for which they are not authorized | ||
| CVE-2026-62246 | Hig | 0.48 | 8.5 | 0.00 | Jul 30, 2026 | Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and… | ||
| CVE-2026-65635 | Hig | 0.47 | — | 0.00 | Jul 30, 2026 | Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attackers to register OpenID Connect clients with administrative privileges through the dynamic client registration entry point. Boruta.Openid.register_client/3… | ||
| CVE-2026-42782 | Hig | 0.47 | 7.2 | 0.01 | May 25, 2026 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer. … | ||
| CVE-2026-5599 | Hig | 0.47 | — | 0.00 | Apr 5, 2026 | A user with API access and "manage users" permission in any venueless world is able to trigger deletion of user accounts in other worlds. | ||
| CVE-2025-41688 | — | Hig | 0.47 | 7.2 | 0.01 | Jul 31, 2025 | A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the implemented LUA sandbox. | |
| CVE-2025-3086 | Hig | 0.46 | 7.1 | 0.00 | Apr 4, 2025 | Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous users views and possibly cause a denial of service | ||
| CVE-2024-23683 | — | Hig | 0.46 | 8.2 | 0.00 | Jan 19, 2024 | Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code. | |
| CVE-2026-57135 | hig | 0.45 | — | — | Jun 18, 2026 | ## Summary The published npm package `praisonai` exports a TypeScript `SandboxExecutor` with a `network-isolated` mode. The CLI lists that mode as: ```text network-isolated No network access (proxy blocked) ``` The implementation does not create a network namespace, firewall… | ||
| CVE-2025-57738 | Hig | 0.42 | 7.2 | 0.23 | Oct 20, 2025 | Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly… | ||
| CVE-2024-55456 | Med | 0.42 | 6.5 | 0.00 | Feb 3, 2025 | lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell | ||
| CVE-2024-57723 | Med | 0.42 | 6.5 | 0.00 | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over. | ||
| CVE-2024-57721 | Med | 0.42 | 6.5 | 0.00 | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path. | ||
| CVE-2024-57720 | Med | 0.42 | 6.5 | 0.00 | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend. | ||
| CVE-2024-30388 | Med | 0.42 | 6.5 | 0.00 | Apr 12, 2024 | An Improper Isolation or Compartmentalization vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on QFX5000 Series and EX Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). If a specific malformed LACP packet is… | ||
| CVE-2026-4282 | Hig | 0.41 | 7.4 | 0.00 | Apr 2, 2026 | A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable… |
- risk 0.49cvss 7.5epss 0.00
Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.
- risk 0.49cvss 7.5epss 0.00
Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each other. This issue resulted in bypass of access control due to the presence of a vulnerable endpoint in Foundry Container Service that…
- risk 0.49cvss 7.6epss 0.01
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a…
- risk 0.49cvss 7.6epss 0.01
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges,…
- risk 0.49cvss 7.6epss 0.00
A user with advanced report application access rights can perform actions for which they are not authorized
- risk 0.48cvss 8.5epss 0.00
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and…
- risk 0.47cvss —epss 0.00
Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attackers to register OpenID Connect clients with administrative privileges through the dynamic client registration entry point. Boruta.Openid.register_client/3…
- risk 0.47cvss 7.2epss 0.01
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer. …
- risk 0.47cvss —epss 0.00
A user with API access and "manage users" permission in any venueless world is able to trigger deletion of user accounts in other worlds.
- risk 0.47cvss 7.2epss 0.01
A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the implemented LUA sandbox.
- risk 0.46cvss 7.1epss 0.00
Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous users views and possibly cause a denial of service
- risk 0.46cvss 8.2epss 0.00
Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code.
- risk 0.45cvss —epss —
## Summary The published npm package `praisonai` exports a TypeScript `SandboxExecutor` with a `network-isolated` mode. The CLI lists that mode as: ```text network-isolated No network access (proxy blocked) ``` The implementation does not create a network namespace, firewall…
- risk 0.42cvss 7.2epss 0.23
Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly…
- risk 0.42cvss 6.5epss 0.00
lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell
- risk 0.42cvss 6.5epss 0.00
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over.
- risk 0.42cvss 6.5epss 0.00
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path.
- risk 0.42cvss 6.5epss 0.00
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend.
- risk 0.42cvss 6.5epss 0.00
An Improper Isolation or Compartmentalization vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on QFX5000 Series and EX Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). If a specific malformed LACP packet is…
- risk 0.41cvss 7.4epss 0.00
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable…