CWE-669— Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.— MITRE CWE catalog
121 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-669page 1 of 3
- CVE-2026-31431CRITICALCVSS 7.8EG 9.0⚠ KEV2026-04-22
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in oper…
- CVE-2021-22900CRITICALCVSS 7.2EG 9.0⚠ KEV2021-05-27
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web inter…
- CVE-2026-75003CRITICALCVSS 9.8EG 9.82026-08-17
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.
- CVE-2025-67895CRITICALCVSS 9.8EG 9.82025-12-17
Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on Airflow 2. The Edge3 provider support in Airflow 2 has been always development-only and…
- CVE-2022-4446CRITICALCVSS 9.8EG 9.82022-12-13
PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.
- CVE-2020-24683CRITICALCVSS 9.8EG 9.82020-12-22
The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the client node (client-side authentication). This is not as secure as having the server validate a…
- CVE-2020-5800CRITICALCVSS 9.8EG 9.82020-12-07
The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and retrieve or modify information that they would not normally have access to.
- CVE-2020-15892CRITICALCVSS 9.8EG 9.82020-07-22
An issue was discovered in apply.cgi on D-Link DAP-1520 devices before 1.10b04Beta02. Whenever a user performs a login action from the web interface, the request values are being forwarded to the ssi binary. On the login page, the web inte…
- CVE-2019-13025CRITICALCVSS 9.8EG 9.82019-10-02
Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Validation. The attacker can send a maliciously modified POST (HTTP) request containing shell commands, which will be execute…
- CVE-2016-5062CRITICALCVSS 9.8EG 9.82016-09-29
The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to execute arbitrary Java code by registering MBeans.
- CVE-2022-20658CRITICALCVSS 9.6EG 9.62022-01-14
A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) and Cisco Unified Contact Center Domain Manager (Unified CCDM) could allow an authenticated, remote attacker to elevate …
- CVE-2026-14151CRITICALCVSS 8.3EG 9.62026-07-01
Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-20194CRITICALCVSS 9.1EG 9.12026-09-16
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal securit…
- CVE-2023-31114CRITICALCVSS 9.1EG 9.12023-06-07
An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer between spheres can cause unintended querying of the SIM status via a crafted application.
- CVE-2026-33265CRITICALCVSS 9.0EG 9.02026-03-18
In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.
- CVE-2025-41660HIGHCVSS 8.8EG 8.82026-03-24
A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.
- CVE-2026-25253HIGHCVSS 8.8EG 8.82026-02-01
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.
- CVE-2021-45891HIGHCVSS 8.8EG 8.82022-04-05
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4., that allows attackers to escalate privileges within the application, since all permission checks are done client-side, not server-side.
- CVE-2021-24602HIGHCVSS 8.8EG 8.82021-08-23
The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page
- CVE-2020-25917HIGHCVSS 8.8EG 8.82020-12-26
Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform, for example a user with "helpdesk" privileges, can perform privileged operations including adding a new administrator …
- CVE-2019-13266HIGHCVSS 8.8EG 8.82019-08-27
TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID …
- CVE-2019-13263HIGHCVSS 8.8EG 8.82019-08-27
D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the …
- CVE-2019-11875HIGHCVSS 8.8EG 8.82019-05-24
In AutomateAppCore.dll in Blue Prism Robotic Process Automation 6.4.0.8445, a vulnerability in access control can be exploited to escalate privileges. The vulnerability allows for abusing the application for fraud or unauthorized access to…
- CVE-2025-41645HIGHCVSS 8.6EG 8.62025-05-13
An unauthenticated remote attacker could use a demo account of the portal to hijack devices that were created in that account by mistake.
- CVE-2026-46448HIGHCVSS 8.5EG 8.52026-06-16
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.
- CVE-2025-34158HIGHCVSS 8.5EG 8.52025-08-21
Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server owner (and a /api/resources call reveals other server…
- CVE-2026-35545HIGHCVSS 8.2EG 8.22026-04-03
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves …
- CVE-2026-24708HIGHCVSS 8.2EG 8.22026-02-18
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to …
- CVE-2022-30236HIGHCVSS 8.2EG 8.22022-06-02
A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow unauthorized access when an attacker uses cross-domain attacks. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
- CVE-2021-21531HIGHCVSS 8.1EG 8.12021-04-30
Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions.
- CVE-2021-20411HIGHCVSS 8.1EG 8.12021-02-12
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to impersonate another user on the system due to incorrectly updating the session identifier. IBM X-Force ID: 198191.
- CVE-2019-11770HIGHCVSS 8.1EG 8.12019-06-14
In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over HTTP instead of HTTPS. Any of these artifacts could have been MITM to maliciously compromise them and infect the build …
- CVE-2019-10248HIGHCVSS 8.1EG 8.12019-04-22
Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts…
- CVE-2025-62775HIGHCVSS 8.0EG 8.02025-10-22
Mercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password.
- CVE-2022-31233HIGHCVSS 6.3EG 8.02022-08-31
Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have ac…
- CVE-2021-36338HIGHCVSS 6.3EG 8.02022-01-21
Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not hav…
- CVE-2026-47574HIGHCVSS 7.8EG 7.82026-09-30
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability where an attacker could cause incorrect resource transfer between spheres. A successful exploit of this vulnerability might lead to code execution, denial of service, escal…
- CVE-2026-103106HIGHCVSS 7.8EG 7.82026-09-30
Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an at…
- CVE-2026-86144HIGHCVSS 7.8EG 7.82026-09-05
In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the …
- CVE-2024-38519HIGHCVSS 7.8EG 7.82024-07-02
`yt-dlp` and `youtube-dl` are command-line audio/video downloaders. Prior to the fixed versions, `yt-dlp` and `youtube-dl` do not limit the extensions of downloaded files, which could lead to arbitrary filenames being created in the downl…
- CVE-2020-1048HIGHCVSS 7.8EG 7.82020-05-21
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated …
- CVE-2026-46447HIGHCVSS 7.7EG 7.72026-06-03
OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.
- CVE-2026-42997HIGHCVSS 7.7EG 7.72026-05-05
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides a…
- CVE-2025-62646HIGHCVSS 7.7EG 7.72025-10-17
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers.
- CVE-2025-59363HIGHCVSS 7.7EG 7.72025-09-14
In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created),
- CVE-2023-32803HIGHCVSS 7.5EG 7.52026-09-14
The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-2349…
- CVE-2023-44104HIGHCVSS 7.5EG 7.52023-10-11
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-44100HIGHCVSS 7.5EG 7.52023-10-11
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-31115HIGHCVSS 7.5EG 7.52023-06-07
An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer between spheres can cause changes to the activation mode of RCS via a crafted application.
- CVE-2021-22806HIGHCVSS 7.5EG 7.52022-02-11
A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unauthorized access when accessing a malicious website. Affected Product: spaceLYnk (V2.6.1 and prior), Wiser for KNX (V2.6.…
Map vulnerabilities like CWE-669 to your infrastructure
EchelonGraph correlates every CVE — across CWE-669 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →