CWE-15— External Control of System or Configuration Setting
One or more system settings or configuration elements can be externally controlled by a user.— MITRE CWE catalog
88 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-15page 1 of 2
- CVE-2026-6973CRITICALCVSS 7.2EG 9.0⚠ KEV2026-05-07
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
- CVE-2026-87987CRITICALCVSS 10.0EG 10.02026-09-11
An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enablin…
- CVE-2026-45087CRITICALCVSS 10.0EG 10.02026-05-27
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server), the server binds to 0.0.0.0:6664 by default and requires no API key unless the…
- CVE-2026-44774CRITICALCVSS 9.9EG 9.92026-05-15
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissions to expose the REST provider handler, bypassing the provi…
- CVE-2026-19593CRITICALCVSS 9.8EG 9.82026-09-01
OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree se…
- CVE-2026-41176CRITICALCVSS 9.8EG 9.82026-04-23
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, including …
- CVE-2026-22708CRITICALCVSS 9.8EG 9.82026-01-14
Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still be executed without appearing in the allowlist and without…
- CVE-2024-4326CRITICALCVSS 9.8EG 9.82024-05-16
A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the `/apply_settings` and `/execute_code` endpoints. Attackers can bypas…
- CVE-2023-50252CRITICALCVSS 9.8EG 9.82023-12-12
php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `<use>` tag that references an `<image>` tag, it merges the attributes from the `<use>` tag to the `<image>` tag. The problem pops up especially …
- CVE-2026-46399CRITICALCVSS 9.4EG 9.42026-06-05
HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0 has an authenticated file overwrite vulnerability. An attacker can exploit this vulnerability to configure malicious Gi…
- CVE-2024-39800CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can…
- CVE-2024-39799CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can…
- CVE-2024-39798CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can…
- CVE-2024-39795CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticat…
- CVE-2024-39794CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticat…
- CVE-2024-39793CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticat…
- CVE-2024-39790CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated H…
- CVE-2024-39789CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated H…
- CVE-2024-39788CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated H…
- CVE-2024-39602CRITICALCVSS 9.1EG 9.12025-01-14
An external config control vulnerability exists in the nas.cgi set_nas() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HT…
- CVE-2024-39280CRITICALCVSS 9.1EG 9.12025-01-14
An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticate…
- CVE-2024-38666CRITICALCVSS 9.1EG 9.12025-01-14
An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an…
- CVE-2021-38453CRITICALCVSS 9.1EG 9.12021-10-22
Some API functions allow interaction with the registry, which includes reading values as well as data modification.
- CVE-2026-1784HIGHCVSS 8.8EG 8.82026-06-02
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controll…
- CVE-2026-41489HIGHCVSS 8.8EG 8.82026-05-11
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to before Core 6.4.2 and FTL 6.6.1, two shell scripts executed as root by systemd (pihole-FTL-prestart.sh and pihol…
- CVE-2026-22177HIGHCVSS 8.8EG 8.82026-03-18
OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars, allowing startup-time code execution. Attackers can inject variables like NODE_OPTIONS or LD_* through configuration …
- CVE-2024-10979HIGHCVSS 8.8EG 8.82024-11-14
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arbitrary code execution, even if the attac…
- CVE-2023-46248HIGHCVSS 8.8EG 8.82023-10-31
Cody is an artificial intelligence (AI) coding assistant. The Cody AI VSCode extension versions 0.10.0 through 0.14.0 are vulnerable to Remote Code Execution under certain conditions. An attacker in control of a malicious repository could …
- CVE-2021-27406HIGHCVSS 8.8EG 8.82022-10-14
An attacker can take leverage on PerFact OpenVPN-Client versions 1.4.1.0 and prior to send the config command from any application running on the local host machine to force the back-end server into initializing a new open-VPN instance wit…
- CVE-2023-4704HIGHCVSS 4.9EG 8.82023-09-01
External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- CVE-2026-85217HIGHCVSS 8.6EG 8.62026-09-10
A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated F…
- CVE-2026-41294HIGHCVSS 8.6EG 8.62026-04-21
OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration, allowing environment variable injection. Attackers can place a malicious .env file in a repository or workspace to override run…
- CVE-2025-0425HIGHCVSS 8.5EG 8.52025-02-18
Via the GUI of the "bestinformed Infoclient", a low-privileged user is by default able to change the server address of the "bestinformed Server" to which this client connects. This is dangerous as the "bestinformed Infoclient" runs with el…
- CVE-2026-107818HIGHCVSS 8.4EG 8.42026-10-09
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mariadb.service unit used /run/mysqld/wsrep-new-cluster during the next service restart. A database…
- CVE-2026-19884HIGHCVSS 8.4EG 8.42026-08-14
In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. This affects applications built on Theia that include the git integration, such …
- CVE-2026-66065HIGHCVSS 8.4EG 8.42026-08-03
Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Several execution-routing keys of the same RC…
- CVE-2026-27203HIGHCVSS 8.3EG 8.32026-02-21
eBay API MCP Server is an open source local MCP server providing AI assistants with comprehensive access to eBay's Sell APIs. All versions are vulnerable to Environment Variable Injection through the updateEnvFile function. The ebay_set_us…
- CVE-2026-16708HIGHCVSS 7.5EG 8.32026-08-14
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration.
- CVE-2026-46485HIGHCVSS 8.2EG 8.22026-07-15
Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality des…
- CVE-2024-51544HIGHCVSS 8.2EG 8.22024-12-05
Service Control vulnerabilities allow access to service restart requests and vm configuration settings. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
- CVE-2024-51543HIGHCVSS 8.2EG 8.22024-12-05
Information Disclosure vulnerabilities allow access to application configuration information. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
- CVE-2023-32349HIGHCVSS 8.0EG 8.02023-05-22
Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter parameters. However, variables for validation checks are stored in an external configuration file. …
- CVE-2024-1488HIGHCVSS 7.3EG 8.02024-02-15
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the c…
- CVE-2026-41384HIGHCVSS 7.8EG 7.82026-04-28
OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows attackers to inject malicious environment variables through workspace configuration. Attackers can craft malicious wor…
- CVE-2026-33092HIGHCVSS 7.8EG 7.82026-04-10
Local privilege escalation due to improper handling of environment variables. The following products are affected: Acronis True Image OEM (macOS) before build 42571, Acronis True Image (macOS) before build 42902.
- CVE-2023-6154HIGHCVSS 7.8EG 7.82024-04-01
A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitdefender Antivirus Free allows an attacker to change the product's expected behavior and po…
- CVE-2021-31338HIGHCVSS 7.8EG 7.82021-08-19
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.0 SP1). Affected devices allow to modify configuration settings over an unauthenticated channel. This could allow a local attacker to escalate privilege…
- CVE-2026-13745HIGHCVSS 7.7EG 7.72026-09-10
A vulnerability in the Gemini CLI prior to version 0.39.1 allows attackers to achieve arbitrary code execution by tricking a victim into starting the CLI within an untrusted directory. The vulnerability is triggered via untrusted .env file…
- CVE-2019-25716HIGHCVSS 7.5EG 7.52026-06-01
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the monitor to reboot by sending a malformed network packet. Attackers can repeatedly send malform…
- CVE-2026-44417HIGHCVSS 7.5EG 7.52026-05-22
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apa…
Map vulnerabilities like CWE-15 to your infrastructure
EchelonGraph correlates every CVE — across CWE-15 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →