VYPR

CWE-653

Improper Isolation or Compartmentalization

ClassDraft

Description

The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

When a weakness occurs in functionality that is accessible by lower-privileged users, then without strong boundaries, an attack might extend the scope of the damage to higher-privileged users.

Hierarchy (View 1000)

CVEs mapped to this weakness (73)

page 4 of 4
  • CVE-2024-43803MedSep 3, 2024
    risk 0.25cvss 4.9epss 0.01

    The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. The `BareMetalHost` (BMH) CRD allows the `userData`, `metaData`, and `networkData` for the provisioned host to be specified as links to Kubernetes Secrets. There are fields for…

  • CVE-2026-71325MedAug 6, 2026
    risk 0.24cvss epss 0.00

    Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant…

  • CVE-2026-5600MedApr 8, 2026
    risk 0.21cvss 4.3epss 0.00

    A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-in events belonging to the respective organizer. This allows an API consumer to access information for all other events under the same …

  • CVE-2024-35281LowMay 13, 2025
    risk 0.16cvss 2.5epss 0.00

    An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron…

  • CVE-2025-41116LowNov 11, 2025
    risk 0.14cvss epss 0.00

    When using the Grafana Databricks Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, it  could result in  the wrong user identifier being used, and information…

  • CVE-2025-3717LowNov 11, 2025
    risk 0.14cvss epss 0.00

    When using the Grafana Snowflake Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, it  could result in  the wrong user identifier being used, and information…

  • CVE-2026-63071CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.00

    Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox. This issue affects Apache Syncope:…

  • CVE-2026-53421CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts. This…

  • CVE-2026-53405CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.00

    Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTask is imported…

  • CVE-2026-15738HigJul 14, 2026
    risk 0.00cvss 8.5epss 0.00

    Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2 might allow an authenticated remote user to intercept, spoof, or deny another namespace's gRPC traffic on a shared Gateway via a crafted HTTPRoute resource. …

  • CVE-2025-6705MedJun 27, 2025
    risk 0.00cvss 5.3epss 0.00

    A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. Specifically, the system’s build scripts were executed without proper isolation, potentially exposing a privileged token. This token enabled…

  • CVE-2024-53855LowNov 27, 2024
    risk 0.00cvss 1.9epss 0.00

    Centurion ERP (Enterprise Rescource Planning) is a simple application developed to provide open source IT management with a large emphasis on the IT Service Management (ITSM) modules. A user who is authenticated and has view permissions for a ticket, can view the tickets of…

  • CVE-2024-49373MedOct 22, 2024
    risk 0.00cvss 4.1epss 0.00

    No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an authenticated user can view projects within organizations they are not apart of. Version 1.2.1 fixes the problem.