CWE-424

CWE-424 · 3 records · 0 with a public proof-of-concept

Records the NVD classes under CWE-424, highest CVSS first.

  1. HIGH 7.7CVE-2026-107352

    Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. Query results, credentials, and Am…

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 6.5CVE-2026-89039

    A caller who can invoke the convert_playwright_script prompt in mcp-k6 can pass a bare file path as the playwright_script argument and receive the contents of any file readable by the user running the server, including SSH keys and cloud credentials in that us…

    AI risk analysis on Exploit-DB.ai →

  3. LOW 3.1CVE-2026-93353

    copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitrary paths outside permitted volume boundaries by exploiting three handlers that bypass the xvol volfla…

    AI risk analysis on Exploit-DB.ai →