VYPR

CWE-653

Improper Isolation or Compartmentalization

ClassDraft

Description

The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

When a weakness occurs in functionality that is accessible by lower-privileged users, then without strong boundaries, an attack might extend the scope of the damage to higher-privileged users.

Hierarchy (View 1000)

CVEs mapped to this weakness (73)

page 3 of 4
  • CVE-2025-21590MedKEVMar 12, 2025
    risk 0.41cvss 4.4epss 0.02

    An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access to the shell is able to inject arbitrary code which can…

  • CVE-2023-1636MedSep 24, 2023
    risk 0.39cvss 6.0epss 0.00

    A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any…

  • CVE-2026-25905MedFeb 9, 2026
    risk 0.38cvss 5.8epss 0.00

    The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any Python code to use the Pyodide APIs to modify the JS environment. This may result in an attacker hijacking the MCP server - for malicious purposes including…

  • CVE-2025-12695MedNov 4, 2025
    risk 0.38cvss 5.9epss 0.00

    The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class.

  • CVE-2026-34775MedApr 4, 2026
    risk 0.37cvss 6.8epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0, the nodeIntegrationInWorker webPreference was not correctly scoped in all configurations. In certain process-sharing…

  • CVE-2026-41155MedJun 12, 2026
    risk 0.36cvss 5.5epss 0.00

    An attacker could cooperatively pass data from one secure GPU process to another secure GPU process through shared secure memory allocations in the kernel module. Additionally, an attacker could disrupt the operation of another secure GPU process leading to image corruption /…

  • CVE-2024-0137MedJan 28, 2025
    risk 0.36cvss 5.5epss 0.00

    NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code running in the host’s network namespace. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a…

  • CVE-2024-35425MedNov 8, 2024
    risk 0.36cvss 5.5epss 0.00

    vmir e8117 was discovered to contain a segmentation violation via the function_prepare_parse function at /src/vmir_function.c.

  • CVE-2023-29580MedApr 12, 2023
    risk 0.36cvss 5.5epss 0.00

    yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/expr.c.

  • CVE-2026-41174MedApr 30, 2026
    risk 0.35cvss 6.4epss 0.00

    Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potential vulnerability in Traefik's Kubernetes CRD provider cross-namespace isolation enforcement. When providers.kubernetesCRD.allowCrossNamespace=false, Traefik…

  • CVE-2025-29781MedMar 17, 2025
    risk 0.35cvss 6.5epss 0.00

    The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. Baremetal Operator enables users to load Secret from arbitrary namespaces upon deployment of the namespace scoped Custom Resource `BMCEventSubscription`. Prior to versions 0.8.1…

  • CVE-2025-26393MedMar 17, 2025
    risk 0.35cvss 5.4epss 0.00

    SolarWinds Service Desk is affected by a broken access control vulnerability. The issue allows authenticated users to escalate privileges, leading to unauthorized data manipulation.

  • CVE-2025-24986MedMar 11, 2025
    risk 0.35cvss 6.5epss 0.01

    Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network.

  • CVE-2025-46215MedNov 18, 2025
    risk 0.34cvss 5.3epss 0.00

    An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to evade the sandboxing scan…

  • CVE-2024-20285MedAug 28, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device. The vulnerability is due to insufficient…

  • CVE-2024-5801MedAug 12, 2024
    risk 0.34cvss epss 0.00

    Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise network security by routing IP-based packets through the host, potentially by-passing firewall, router, or NAC filtering.

  • CVE-2024-8118MedSep 26, 2024
    risk 0.33cvss epss 0.01

    In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

  • CVE-2026-40968MedApr 28, 2026
    risk 0.27cvss 4.2epss 0.00

    When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unauthenticated request on the same thread. This may allow the subsequent user to gain escalated permissions. …

  • CVE-2026-4325MedApr 2, 2026
    risk 0.27cvss 5.3epss 0.00

    A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use entries, which can enable the replay of consumed action tokens, such as password…

  • CVE-2025-27027MedJul 9, 2025
    risk 0.27cvss 4.1epss 0.00

    A user with vpuser credentials that opens an SSH connection to the device, gets a restricted shell rbash that allows only a small list of allowed commands. This vulnerability enables the user to get a full-featured Linux shell, bypassing the rbash restrictions.