By weakness (CWE)
CWE-20: related vulnerabilities
CVEs classified under CWE-20. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
358 published vulnerabilities · page 4 of 4
- CVE-2026-9210MEDIUM 4.5
A NETGEAR router firmware vulnerability allows authenticated administrators on the local network to bypass input validation controls and make unauthorized changes to router software and settings. An attacker with admin credentials and direct network access can modify core router functionality without proper authorization checks. This is a localized threat that requires existing administrative access to exploit, limiting its blast radius but still representing a significant risk to network integrity if admin credentials are compromised.
- CVE-2026-3620MEDIUM 4.4
The Word Replacer plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability affecting all versions through 0.4. An attacker with administrator-level access can inject malicious scripts through the plugin's 'replacement' parameter. These scripts persist in the WordPress database and execute whenever any user visits an affected page, potentially allowing credential theft, session hijacking, or defacement. The vulnerability stems from inadequate input validation and output encoding in the plugin code.
- CVE-2026-11031MEDIUM 4.3
Google Chrome's Password Manager fails to properly validate input from network traffic before displaying it to users. An attacker can craft malicious network data that tricks the Password Manager interface into showing fake or misleading information—for example, a phishing prompt that looks legitimate. This affects Chrome versions before 149.0.7827.53 on Windows, macOS, and Linux.
- CVE-2026-11126MEDIUM 4.3
A flaw in Google Chrome's Developer Tools (DevTools) allows an attacker to access data from different websites if they can trick a user into installing a malicious browser extension. The vulnerability has a CVSS score of 4.3 (Medium severity) and requires user interaction—specifically, the user must be convinced to install the malicious extension. Once installed, the crafted extension can exploit improper input validation in DevTools to leak cross-origin data that should normally be protected by browser security policies.
- CVE-2026-11192MEDIUM 4.3
Google Chrome's password manager has a flaw that fails to properly check information coming from the network. An attacker can exploit this by sending crafted network traffic to trick the browser's UI into displaying fake or misleading content—for example, mimicking legitimate login prompts or security warnings. The attacker cannot steal data or crash the browser, but they can manipulate what users see, potentially leading to credential theft or social engineering attacks if the spoofed interface convinces users to enter sensitive information.
- CVE-2026-11221MEDIUM 4.3
A weakness in Google Chrome's PointerLock feature allows a threat actor who has already gained control of the browser's renderer process to deceive users through fake on-screen elements. The attacker would craft a malicious HTML page that tricks the browser into displaying misleading UI, potentially impersonating legitimate interface elements. This requires the renderer process to be compromised first, making it a secondary attack that typically follows another successful exploit.
- CVE-2026-11259MEDIUM 4.3
Google Chrome versions before 149.0.7827.53 contain a flaw in how the Cast feature validates user-supplied input. This allows an attacker to craft a malicious webpage that, when visited, can bypass Chrome's same-origin policy—a critical security boundary that prevents websites from accessing data belonging to other sites. The attack requires user interaction (visiting the page) but requires no special privileges. While Chromium rates the underlying severity as Low, the ability to circumvent same-origin policy elevates practical risk.
- CVE-2026-11261MEDIUM 4.3
Google Chrome versions before 149.0.7827.53 contain a flaw in how it handles PDF rendering that could allow an attacker to trick users into believing they're viewing legitimate content when they're not. If an attacker has already compromised Chrome's rendering engine (the component that displays web pages), they can craft a specially designed HTML page to perform UI spoofing—making fake buttons, warnings, or other interface elements appear authentic. This is a medium-severity issue because it requires both a prior compromise of the renderer process and user interaction to be exploited.
- CVE-2026-11280MEDIUM 4.3
A flaw in Google Chrome's sign-in interface on iOS allows an attacker to trick users with a fake login screen. By crafting a malicious web page, an attacker could make it appear that a legitimate Chrome sign-in prompt is appearing, potentially deceiving users into entering credentials or sensitive information. The vulnerability requires user interaction—visiting a crafted page—but does not require authentication or special privileges to attempt. While Google classifies this at low severity internally, the CVSS score reflects medium risk due to the integrity impact of potential credential theft or trust erosion.
- CVE-2026-11286MEDIUM 4.3
A flaw in Google Chrome's Wallet component allows attackers who have already compromised a browser's renderer process to trick users with fake UI elements displayed on a web page. This requires the attacker to first gain control of the renderer—the part of the browser that displays web content—which is a significant prerequisite but not impossible in real-world scenarios where other vulnerabilities or social engineering may be chained together.
- CVE-2026-11685MEDIUM 4.3
Google Chrome on macOS contains a flaw in how it handles media capture permissions that could allow an attacker to trick you into revealing data meant to be private to a specific website. By crafting a malicious webpage, an attacker can bypass Chrome's protections and leak information across website boundaries—essentially stealing data that should stay isolated to one origin. The vulnerability requires user interaction, such as visiting a malicious page, but does not require special privileges or system-level access.
- CVE-2026-13865MEDIUM 4.3
Google Chrome versions before 150.0.7871.47 contain a flaw that allows attackers to trick users with fake interface elements. An attacker could craft a malicious website that makes parts of the browser or page look different from what they actually are—for example, spoofing a login prompt or security warning. The vulnerability requires user interaction (visiting a crafted page) but doesn't require special privileges or browser extensions to exploit.
- CVE-2026-13959MEDIUM 4.3
Google Chrome versions before 150.0.7871.47 contain a flaw in Blink (Chrome's rendering engine) that fails to properly validate user input in HTML pages. An attacker can exploit this by crafting a malicious HTML page that, when visited, bypasses the same-origin policy—a critical browser security boundary that prevents websites from accessing data or performing actions on behalf of other sites. The vulnerability requires user interaction (visiting a malicious page) but poses a moderate integrity risk.
- CVE-2026-13991MEDIUM 4.3
A vulnerability in Chrome for iOS allows attackers to trick users through fake interface elements on specially crafted websites. When a user visits a malicious page, an attacker can make it appear as though legitimate interface elements (like buttons or address bars) are showing something they're not, potentially tricking the user into taking unintended actions. This requires user interaction—the user must visit the malicious site and interact with it—but the barrier to exploitation is low.
- CVE-2026-13995MEDIUM 4.3
A flaw in Google Chrome's autofill feature on Android devices allows an attacker to trick users with a fake website. The vulnerability exists because the browser doesn't properly validate input when displaying autofill suggestions, giving attackers an opening to create deceptive pages that mimic legitimate interfaces. This is a relatively low-risk issue—it requires user interaction and only affects how information appears on screen, not data theft or system crashes—but it's worth patching because social engineering attacks that fool users into revealing credentials remain a persistent threat.
- CVE-2026-13999MEDIUM 4.3
Google Chrome versions before 150.0.7871.47 contain a flaw that allows malicious browser extensions to trick users visually by displaying fake UI elements. An attacker must first convince a user to install a malicious extension, but once installed, the extension can spoof Chrome's user interface to deceive the user. This is classified as a medium-severity issue because it requires user interaction to install the extension and doesn't directly compromise system data or functionality on its own.
- CVE-2026-14020MEDIUM 4.3
A flaw in Google Chrome's WebXR implementation allows a remote attacker to trick users into thinking they're interacting with legitimate interface elements when they're actually engaging with spoofed content. The vulnerability requires the attacker to first compromise Chrome's renderer process—the component that draws web pages—and then serve a malicious webpage to execute the UI spoofing attack. While the initial compromise is a prerequisite, once achieved, users can be deceived without additional interaction beyond normal web browsing.
- CVE-2026-14045MEDIUM 4.3
A flaw in Google Chrome's network handling allows attackers who have already compromised the browser's renderer process to steal sensitive data from websites the user visits. The attacker would craft a malicious webpage designed to leak information across security boundaries that normally keep data from different websites separate. This requires the attacker to have already gained control of Chrome's rendering engine, making this a post-compromise issue rather than a remote code execution vector.
- CVE-2026-14066MEDIUM 4.3
A vulnerability in Google Chrome for iOS allows attackers to bypass navigation restrictions through a specially crafted webpage. An attacker could create a malicious HTML page that, when visited by a user, circumvents Chrome's security controls that normally prevent unwanted navigation. This requires user interaction—the user must visit the malicious page—but does not require the attacker to have special privileges. The impact is limited to integrity concerns rather than data theft or system disruption.
- CVE-2026-14073MEDIUM 4.3
A flaw in Google Chrome's WebXR implementation fails to properly validate user-supplied input before processing navigation commands. An attacker can craft a malicious webpage that, when visited by a user, bypasses Chrome's navigation restrictions—allowing the page to navigate to unexpected URLs or perform unwanted redirects. The vulnerability requires user interaction (clicking or visiting the page) and affects Chrome versions prior to 150.0.7871.47. The issue stems from insufficient input sanitization in the WebXR code path, a component used for virtual and augmented reality experiences in the browser.
- CVE-2026-14080MEDIUM 4.3
Google Chrome on Android versions before 150.0.7871.47 contain a flaw in the TabSwitcher component that fails to properly validate untrusted network data. An attacker can exploit this to bypass navigation restrictions—essentially forcing users to visit pages they shouldn't be able to reach—by sending specially crafted network traffic. The vulnerability requires user interaction (clicking or tapping) to trigger, but doesn't compromise data confidentiality or system availability.
- CVE-2026-14089MEDIUM 4.3
A flaw in Google Chrome's popup blocker allowed an attacker who had already gained control of Chrome's renderer process to trick users into seeing fake interface elements. The vulnerability stems from inadequate checking of user-supplied input, making it possible to craft a malicious webpage that displays spoofed UI when opened in the compromised renderer. This is a low-severity issue on Chromium's scale, though the CVSS rating reflects medium risk due to the user interaction required and limited scope of impact.
- CVE-2026-14116MEDIUM 4.3
Google Chrome versions before 150.0.7871.47 contain a vulnerability in the Developer Tools (DevTools) feature that can expose sensitive data across different websites. The flaw occurs because Chrome fails to properly validate user input within DevTools. An attacker can craft a malicious webpage that, if a user interacts with it in a specific way while DevTools is active, could leak information that should remain isolated between different websites. This is a user-interaction attack—the victim must perform deliberate actions for the vulnerability to be exploited.
- CVE-2026-14127MEDIUM 4.3
Google Chrome versions prior to 150.0.7871.47 contain a flaw in how the browser handles printing functionality that could allow an attacker to trick users into believing they are interacting with legitimate content when they are not. The vulnerability requires the attacker to have first compromised the Chrome renderer process—the sandboxed component responsible for displaying web content—and then use a specially crafted webpage to create a fake or misleading user interface. While the underlying issue is classified as low severity by the Chromium project, the CVSS scoring reflects the user interaction required and the limited scope of potential impact.
- CVE-2026-14130MEDIUM 4.3
Google Chrome versions before 150.0.7871.47 contain a flaw in the browser's address bar (Omnibox) security indicators that allows an attacker to deceive users through visual spoofing. When a user visits a malicious webpage, the attacker can craft HTML content that makes the browser's security UI display false information—such as misleading indicators about the site's legitimacy or HTTPS status. The vulnerability requires user interaction (visiting the crafted page) but does not directly compromise data confidentiality or system availability; the primary risk is user deception leading to credential theft or other social engineering attacks.
- CVE-2026-14140MEDIUM 4.3
Google Chrome on Android versions before 150.0.7871.47 contains a vulnerability that allows attackers to deceive users through fake interface elements. An attacker can craft a malicious web page that, when visited, displays misleading UI elements—such as fake prompts, buttons, or address bars—to trick users into performing unintended actions. The vulnerability stems from insufficient validation of user-supplied input and does not require the attacker to have any special privileges or access. However, the user must actively visit a malicious page and interact with it for the attack to succeed.
- CVE-2026-15124MEDIUM 4.3
Google Chrome versions before 150.0.7871.115 contain a weakness in how the browser enforces the same-origin policy, a critical security boundary that prevents websites from accessing data belonging to other websites. An attacker can craft a malicious HTML page that, when visited by a user, exploits this weakness to read sensitive information—such as passwords or authentication tokens—from other websites you're logged into. The attack requires user interaction (visiting the malicious page) but doesn't need any special privileges or complex technical setup.
- CVE-2026-15131MEDIUM 4.3
Google Chrome versions before 150.0.7871.115 contain a flaw in how the browser handles navigation that allows an attacker to bypass site isolation, a core security boundary in Chrome. By crafting a malicious HTML page, a remote attacker can trick a user into visiting it, potentially allowing unauthorized access to data from other websites the user has open. The attack requires user interaction but no special privileges. Google rates this as Medium severity.
- CVE-2026-43708MEDIUM 4.3
A cross-origin data exfiltration vulnerability in Apple's WebKit rendering engine affects Safari and multiple Apple operating systems. A malicious website can extract user data that should remain isolated to the user's own origin, bypassing the browser's same-origin policy. Apple has patched this issue across Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS with improved input validation to enforce proper origin boundaries.
- CVE-2026-50569MEDIUM 4.3
Fission, an open-source Kubernetes serverless framework, contains a validation bypass in its HTTP trigger configuration. Prior to version 1.25.0, two URL-related fields—RelativeURL and Prefix—were not properly validated when HTTPTrigger resources were created directly through kubectl or the Kubernetes REST API. While these fields were validated at the CLI level, the validation logic was absent from the core application and its API server rules. This means an attacker with Kubernetes API access could bypass URL restrictions by creating or modifying HTTPTrigger resources directly, potentially routing traffic to unintended functions or exposing restricted endpoints.
- CVE-2026-56333MEDIUM 4.3
Capgo versions prior to 12.128.2 contain a vulnerability that allows authenticated organization administrators to bypass security validation checks and set invalid security policies. An authenticated attacker with admin privileges can directly modify the organization database table to circumvent field-level validation, potentially setting insecure values for critical parameters like API key expiration periods. This is an internal privilege abuse risk rather than a remote, unauthenticated attack vector.
- CVE-2026-12453MEDIUM 4.2
Google Chrome versions before 149.0.7827.155 contain a flaw where insufficient input validation allows an attacker who has already compromised the browser's renderer process to circumvent the same-origin policy through a specially crafted webpage. This means a sandboxed renderer could potentially access or modify data from websites it should not be able to reach, though the attacker must first gain control of the renderer itself—a significant prerequisite.
- CVE-2026-12456MEDIUM 4.2
A vulnerability in how Google Chrome handles extensions before version 149.0.7827.155 allows a malicious extension to bypass the same-origin policy, which normally prevents web pages from accessing data belonging to other websites. An attacker would need to trick a user into installing a specially crafted malicious extension. If successful, the extension could read or modify sensitive information from other websites the user visits. This is a user-consent attack—the user must be socially engineered into installing the extension first.
- CVE-2026-13024MEDIUM 4.2
Google Chrome versions prior to 149.0.7827.197 contain a flaw in how it validates user input during navigation operations. An attacker who has already compromised Chrome's renderer process—the component that interprets and displays web content—can exploit this weakness to bypass Chrome's site isolation security feature. Site isolation is a critical defense that prevents malicious websites from accessing data belonging to other sites. This vulnerability requires an attacker to have already gained control of the renderer process, making it a secondary attack that follows initial compromise.
- CVE-2026-14137MEDIUM 4.2
A vulnerability in Chrome for iOS allows attackers to trick users into performing specific gestures on a crafted webpage, resulting in fake UI elements appearing to come from Chrome itself. This 'UI spoofing' attack could mislead users about the source or nature of content they're interacting with, though the underlying browser functionality and user data remain protected. The attack requires user interaction and is rated Medium severity.
- CVE-2026-9986MEDIUM 4.2
CVE-2026-9986 is a UI spoofing vulnerability in Google Chrome's OptimizationGuide component that could let an attacker deceive users about what they're seeing on a webpage. The vulnerability requires the attacker to have already compromised Chrome's rendering process—the engine that draws web content. While this limits the immediate attack scope, it represents a meaningful escalation risk for adversaries who have achieved code execution in that sandboxed component. The flaw stems from inadequate validation of user-supplied input before it's used to generate on-screen elements.
- CVE-2026-30963LOW 3.9
Capsule is a Kubernetes framework that uses webhooks to prevent tenant administrators from hijacking namespaces—essentially taking control of cluster resources they shouldn't own. The framework checks most update requests, but it misses two specific APIs (namespace/status and namespace/finalize subresources) that can also change namespace ownership markers. Before version 0.13.0, a tenant admin with permission to use these subresources could bypass the webhook protection and seize a namespace. Version 0.13.0 patches this gap by ensuring the webhook intercepts both subresource types.
- CVE-2026-45642LOW 3.9
CVE-2026-45642 affects Microsoft's Azure Attestation and Device Health Attestation services, which are used to verify the integrity and trustworthiness of devices and systems. The vulnerability stems from inadequate validation of user-supplied input, allowing an attacker who already has physical access and elevated privileges on a target system to spoof attestation results. This means an attacker could make a compromised or malicious device appear legitimate to systems that rely on attestation checks. The attack requires both physical proximity to the device and administrative-level access, significantly limiting real-world exposure.
- CVE-2026-46584LOW 3.7
Apache Camel's mail component has an input validation flaw that allows untrusted data to override email sending configuration. If a Camel route accepts input from external sources (like HTTP requests or message queues) and passes it directly to an SMTP/SMTPS producer without filtering, an attacker can inject malicious mail configuration headers. On older versions (before 4.19.0), this could redirect email traffic to attacker-controlled servers, exposing configured SMTP credentials. On newer versions, the attack is limited to weakening security settings or intercepting message content. The vulnerability only materializes in routes that lack proper input sanitization.
- CVE-2026-53537LOW 3.7
Python-Multipart before version 0.0.30 contains a header parsing vulnerability that could allow an attacker to bypass security controls. The library uses email message parsing for Content-Disposition and Content-Type headers, which automatically decodes RFC 2231/5987 extended parameter syntax (like filename*=). This decoding is not supposed to happen in multipart form data per the relevant RFC standard. An attacker can craft a specially formatted header that gets decoded differently by the vulnerable library than by upstream security tools (WAFs, proxies), potentially smuggling through a different field name or filename than inspectors expect. The risk is relatively low because successful exploitation requires specific conditions and produces only minor integrity issues, not data exposure or system unavailability.
- CVE-2026-48288LOW 3.5
Adobe Experience Manager contains a flaw in how it validates user input that can allow a logged-in attacker to bypass certain security controls and gain unauthorized write permissions. The attacker must trick a victim into visiting a malicious link or interacting with a compromised page, making this a lower-risk issue in practice. Affected versions include 6.5.24, LTS SP1, 2026.04 and earlier.
- CVE-2026-48289LOW 3.5
Adobe Experience Manager contains a vulnerability in how it validates user input that could allow a low-privileged attacker to bypass security controls and gain unauthorized write access to content. The attack requires the victim to visit a malicious link or interact with a compromised webpage, making it a practical but not trivial threat in environments where AEM is exposed to users. This is not currently listed as exploited in the wild.
- CVE-2026-0142LOW 3.3
CVE-2026-0142 is a local information disclosure vulnerability in Android's AVB (Android Verified Boot) RSA key parsing code. A local user can trigger an out-of-bounds memory read by supplying malformed key data, potentially exposing sensitive information from adjacent memory. The flaw requires only local access and user-level privileges—no special permissions or user interaction is required to exploit it.
- CVE-2026-13942LOW 3.3
A vulnerability in Google Chrome's video capture implementation on ChromeOS allows a local attacker to create fake UI elements through a specially crafted web page. The attacker must already have local access to the device and the user must interact with the malicious page, but the attack only affects the visual presentation of the interface—it cannot steal data or crash the system.
- CVE-2026-13955LOW 3.3
Google Chrome on Android contains a UI spoofing vulnerability in its CustomTabs feature that could allow a local attacker to deceive users by manipulating the app's visual appearance. The vulnerability stems from insufficient validation when processing untrusted input from malicious files. An attacker would need local access to the device and user interaction (such as opening a file) to exploit it. The attack surface is limited because it requires both proximity and user action, and the impact is restricted to visual deception rather than data theft or system compromise.
- CVE-2026-15115LOW 3.3
A vulnerability in Google Chrome on Android allows a local attacker to bypass the same-origin policy—a core browser security feature that prevents websites from accessing data from other origins—through a specially crafted HTML page. The issue stems from insufficient validation of user-supplied input in the WebAppInstalls component. An attacker with local access to the device would need to trick a user into visiting a malicious webpage to exploit this. The vulnerability was patched in Chrome version 150.0.7871.115.
- CVE-2026-11240LOW 3.1
CVE-2026-11240 is a low-severity input validation flaw in Google Chrome's Loader component that allows a remote attacker to bypass the browser's site isolation security feature, but only if they have already compromised the renderer process. Site isolation is Chrome's defense mechanism that runs each website in a separate process to prevent one compromised site from accessing data from another. An attacker would need to deliver a specially crafted HTML page to exploit this, making it a post-compromise risk rather than a direct remote code execution vector. The vulnerability affects Chrome versions prior to 149.0.7827.53.
- CVE-2026-11244LOW 3.1
CVE-2026-11244 is a low-severity flaw in Google Chrome's WebAuthentication feature that allows inadequate validation of user-supplied input. An attacker with prior access to Chrome's renderer process—the component responsible for displaying web pages—could craft a malicious HTML page to circumvent the browser's same-origin policy, a fundamental security boundary that prevents scripts from one website accessing data from another. This is not a direct remote code execution and requires both renderer process compromise and user interaction to succeed.
- CVE-2026-11251LOW 3.1
A flaw in Chrome's password manager allows a sophisticated attacker to read stored password information if they can first compromise Chrome's renderer process through a malicious web page. The vulnerability requires multiple conditions to exploit: the attacker must already control the rendering engine, the user must interact with the page, and the attack surface is limited to sensitive credential disclosure. Chrome versions before 149.0.7827.53 are affected. This is not a zero-click issue and does not allow code execution or system-level access.
- CVE-2026-11675LOW 3.1
Google Chrome contained a memory reading vulnerability in its Skia graphics library that could allow an attacker to steal sensitive data from other websites. The attacker would first need to compromise Chrome's renderer process—the sandboxed component that handles web page rendering—and then trick a user into visiting a specially crafted webpage. If successful, the flaw could leak cross-origin data, meaning information from a different website than the one the user thought they were visiting. This vulnerability affects Chrome versions prior to 149.0.7827.103 across Windows, macOS, and Linux systems.
- CVE-2026-11686LOW 3.1
A flaw in Google Chrome's Dawn graphics library on macOS allows an attacker who has already compromised the browser's renderer process to trick the system into leaking data from other websites. The vulnerability requires the attacker to already have control over the renderer and the user to interact with a malicious webpage, making it a limited but real risk in scenarios where renderer escapes are already being exploited.
- CVE-2026-11691LOW 3.1
Google Chrome contained a flaw in its New Tab Page that could allow attackers who had already compromised Chrome's renderer process to steal data from websites across different origins. The vulnerability required an attacker to have already broken into the renderer—the sandboxed component that runs web content—and then trick a user into visiting a malicious HTML page. While the Chromium security team rated this High severity internally, the calculated CVSS score is Low (3.1) because the attack requires both prior renderer compromise and user interaction.
- CVE-2026-12017LOW 3.1
Google Chrome versions before 149.0.7827.115 contain a flaw in how browser extensions are implemented that could allow an attacker who has already compromised Chrome's rendering engine to escape site isolation—the security boundary that prevents malicious websites from accessing data belonging to other websites. The attacker would need to trick a user into viewing a specially crafted webpage, but the core vulnerability requires prior control of the renderer process, which significantly limits real-world attack scope.
- CVE-2026-13939LOW 3.1
A flaw in Google Chrome's WebShare feature on Android devices could allow an attacker who has already compromised the browser's rendering engine to trick users into thinking they are interacting with legitimate interface elements when they are actually seeing forged content. The vulnerability requires the attacker to have significant pre-existing access to the browser process and relies on user interaction, making it a limited-impact issue in practice.
- CVE-2026-56325LOW 3.1
Capgo versions before 12.128.2 have a flaw in how they look up application identifiers when serving preview content. Instead of checking for exact matches, the system uses pattern matching that treats underscore characters as wildcards—similar to how some database queries work. An attacker with an account on Capgo can exploit this by creating apps with slightly different names that leverage these wildcard behaviors, potentially breaking preview functionality for legitimate applications or causing confusion about which app is being accessed.
- CVE-2026-9950LOW 3.1
A same-origin policy bypass vulnerability exists in Google Chrome on iOS versions prior to 148.0.7778.216. The flaw stems from insufficient validation of untrusted input that allows an attacker who has already compromised Chrome's renderer process to craft a malicious HTML page that circumvents browser security boundaries. This means an attacker could potentially access data or perform actions from a different website origin than the one a user is visiting, but only if the renderer process has already been compromised through another attack vector.
- CVE-2026-44367LOW 2.7
Klaw, a Kafka topic management and governance platform, contains a vulnerability in how it handles usernames during registration and login. The system doesn't consistently apply case sensitivity rules—treating 'Admin' and 'admin' as different or the same depending on the operation—which allows authenticated users with administrative privileges to deliberately lock out accounts or trigger denial of service conditions. This is a low-severity issue requiring administrative access to exploit, but it can impact operational availability if administrators use it maliciously or if the inconsistency is exploited in targeted attacks. The flaw was fixed in version 2.10.4.
- CVE-2026-45076LOW 2.7
Synapse, an open-source Matrix homeserver implementation used for federated messaging, contains a flaw in how it handles room history in cross-server deployments. Malicious homeservers can craft specially formed room events that cause Synapse instances to withhold historical messages from clients requesting older conversation data. Users may see incomplete chat histories or missing messages when paginating through room archives. This is a low-severity issue because it requires a compromised or malicious federated peer and affects data availability rather than confidentiality or integrity.