By weakness (CWE)
CWE-425: related vulnerabilities
CVEs classified under CWE-425. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
4 published vulnerabilities
- CVE-2026-10521HIGH 7.2
CVE-2026-10521 is a high-severity vulnerability that allows an attacker with elevated privileges to access a hidden configuration interface that should be restricted from all users. By exploiting this unauthorized access, an attacker can modify critical program parameters, potentially compromising the confidentiality, integrity, and availability of the affected system. This represents a complete breakdown of security controls for the impacted application.
- CVE-2026-13533MEDIUM 5.3
Cockpit CMS versions up to 0.12.2 contain a vulnerability in its YAML configuration handler that allows unauthorized file access. An attacker can remotely read sensitive files or access restricted directories without authentication. The issue stems from improper handling of YAML parsing in the configuration module, and exploit code is publicly available. This is a disclosure made without vendor cooperation.
- CVE-2026-11986MEDIUM 4.9
Keycloak's admin-ui-ext component has a permission-checking flaw that allows limited administrators to strip high-privilege roles from other users or administrators. An attacker with delegated admin rights can exploit bulk role-removal endpoints to bypass intended access controls, potentially locking out legitimate administrators or escalating their own influence within the system.
- CVE-2026-9610LOW 2.3
IBM Datacap and Datacap Navigator versions 9.1.7, 9.1.8, and 9.1.9 contain a flaw where certain features or data are accessible directly via URL without proper authorization checks, even though those features are not advertised in the user interface. An attacker with local access and elevated privileges could bypass intended security boundaries to view sensitive information.