CWE-653— Improper Isolation or Compartmentalization
The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.— MITRE CWE catalog
84 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-653page 1 of 2
- CVE-2025-21590CRITICALCVSS 4.4EG 9.0⚠ KEV2025-03-12
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access to the shell is ab…
- CVE-2026-44005CRITICALCVSS 10.0EG 10.02026-05-13
vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and …
- CVE-2026-43997CRITICALCVSS 10.0EG 10.02026-05-13
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one example would be using HostObject.getOwnPropertySymbols to o…
- CVE-2026-26332CRITICALCVSS 10.0EG 10.02026-05-04
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in version 3.11.0.
- CVE-2026-4692CRITICALCVSS 10.0EG 10.02026-03-24
Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
- CVE-2026-108263CRITICALCVSS 9.9EG 9.92026-10-09
Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/…
- CVE-2026-53421CRITICALCVSS 9.8EG 9.82026-07-20
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) …
- CVE-2026-53405CRITICALCVSS 9.8EG 9.82026-07-20
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process contain…
- CVE-2026-63071CRITICALCVSS 9.8EG 9.82026-07-20
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbo…
- CVE-2026-44009CRITICALCVSS 9.8EG 9.82026-05-13
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.
- CVE-2026-8401CRITICALCVSS 9.8EG 9.82026-05-12
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.
- CVE-2026-26956CRITICALCVSS 9.8EG 9.82026-05-04
vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooper…
- CVE-2026-24781CRITICALCVSS 9.8EG 9.82026-05-04
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can escape from the VM2 sandbox and execute ar…
- CVE-2026-34775CRITICALCVSS 9.8EG 9.82026-04-04
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0, the nodeIntegrationInWorker webPreference was not correctly scoped in all configu…
- CVE-2025-1974CRITICALCVSS 9.8EG 9.82025-03-25
A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to …
- CVE-2024-33768CRITICALCVSS 9.8EG 9.82024-05-01
lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source_over.
- CVE-2026-95699CRITICALCVSS 9.6EG 9.62026-09-24
Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devic…
- CVE-2026-12297CRITICALCVSS 9.6EG 9.62026-06-16
Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
- CVE-2026-12295CRITICALCVSS 9.6EG 9.62026-06-16
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
- CVE-2026-0542CRITICALCVSS 9.2EG 9.22026-02-25
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow San…
- CVE-2025-4083CRITICALCVSS 9.1EG 9.12025-04-29
A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox esc…
- CVE-2026-102125HIGHCVSS 8.8EG 8.82026-09-30
The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the code running inside it. Code already executing within that sandbox could potentially escape its confinement and act with the privileges of the…
- CVE-2026-82964HIGHCVSS 8.8EG 8.82026-09-16
Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox v…
- CVE-2025-5476HIGHCVSS 8.8EG 8.82025-06-21
Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX8500 devices. Authentication is not required to exploit …
- CVE-2026-62246HIGHCVSS 8.5EG 8.52026-07-30
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreS…
- CVE-2026-15738HIGHCVSS 8.5EG 8.52026-07-14
Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2 might allow an authenticated remote user to intercept, spoof, or deny another namespace's gRPC traffic on a shared Gat…
- CVE-2026-65635HIGHCVSS 8.3EG 8.32026-07-30
Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attackers to register OpenID Connect clients with administrative privileges through the dynamic client registration entry poi…
- CVE-2024-23683HIGHCVSS 8.2EG 8.22024-01-19
Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim execute…
- CVE-2024-23682HIGHCVSS 8.2EG 8.22024-01-19
Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts. An attacker can abuse this issue to execute arbitrary Java when a victim executes the s…
- CVE-2025-12805HIGHCVSS 8.1EG 8.12026-03-26
A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to Llama Stack services deployed in other namespaces via direct network requests, because no NetworkPolicy restricts acces…
- CVE-2023-1305HIGHCVSS 8.1EG 8.12023-03-21
An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided those files can be parsed as yaml or JSON. This issue was resolved in the Managed and SaaS deployments on February 1, …
- CVE-2025-34201HIGHCVSS 7.8EG 7.82025-09-19
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) run many Docker containers on shared internal networks without firewalling or segmentation between instances. A compromise of any single …
- CVE-2025-20109HIGHCVSS 7.8EG 7.82025-08-12
Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2026-57135HIGHCVSS 7.6EG 7.62026-06-18
PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment v…
- CVE-2024-0136HIGHCVSS 7.6EG 7.62025-01-28
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDI…
- CVE-2024-0135HIGHCVSS 7.6EG 7.62025-01-28
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit of this vulnerability may lead to code execution, denial of s…
- CVE-2024-47520HIGHCVSS 7.6EG 7.62025-01-10
A user with advanced report application access rights can perform actions for which they are not authorized
- CVE-2026-8945HIGHCVSS 7.5EG 7.52026-05-19
Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.
- CVE-2025-53710HIGHCVSS 7.5EG 7.52025-12-18
Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each other. This issue resulted in bypass of access control due to the presence of a vulnerable en…
- CVE-2024-6323HIGHCVSS 7.5EG 7.52024-06-27
Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.
- CVE-2026-4282HIGHCVSS 7.4EG 7.42026-04-02
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can…
- CVE-2026-105643HIGHCVSS 7.3EG 7.32026-10-05
Ghost is a Node.js content management system. From version 6.34.0 until 6.67.0, embed cards in the Ghost editor could bypass protections against stored cross-site scripting. Any staff user, including Contributors, could store scripts in po…
- CVE-2026-5599HIGHCVSS 7.3EG 7.32026-04-05
A user with API access and "manage users" permission in any venueless world is able to trigger deletion of user accounts in other worlds.
- CVE-2026-42782HIGHCVSS 7.2EG 7.22026-05-25
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution …
- CVE-2025-57738HIGHCVSS 7.2EG 7.22025-10-20
Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, wi…
- CVE-2025-41688HIGHCVSS 7.2EG 7.22025-07-31
A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the implemented LUA sandbox.
- CVE-2025-3086HIGHCVSS 7.1EG 7.12025-04-04
Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous users views and possibly cause a denial of service
- CVE-2025-29781MEDIUMCVSS 6.5EG 6.52025-03-17
The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. Baremetal Operator enables users to load Secret from arbitrary namespaces upon deployment of the namespace scoped Custom Resource `BMCEventS…
- CVE-2025-24986MEDIUMCVSS 6.5EG 6.52025-03-11
Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network.
- CVE-2024-55456MEDIUMCVSS 6.5EG 6.52025-02-03
lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell
Map vulnerabilities like CWE-653 to your infrastructure
EchelonGraph correlates every CVE — across CWE-653 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →