CWE-441

CWE-441 · 11 records · 8 with a public proof-of-concept

Records the NVD classes under CWE-441, highest CVSS first.

  1. CRITICAL 9.9CVE-2026-100706public PoC

    kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can …

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.1CVE-2026-44945public PoC

    A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transit…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.6CVE-2026-77255public PoC

    MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira update_issue attachments argument is converted into local paths and routed to the attachment upload implementation without workspace …

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.4CVE-2026-77246public PoC

    MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, an HTTP transport deployment with READ_ONLY_MODE=false accepts a request without an Authorization identity and permits attacker-controlled Atl…

    mcp atlassian

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.3CVE-2026-72668

    Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-pr…

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.2CVE-2026-75886

    A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of the `openshift-session-token` cookie. This allows the attacker to send req…

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 7.1CVE-2026-100625public PoC

    Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_backend/public/build/upload.ts) that authorizes a caller against a single build job identified by the supplied builder_job_id and validates only that job's stored upload_path, but t…

    AI risk analysis on Exploit-DB.ai →

  8. MEDIUM 4.8CVE-2026-91742

    Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium security severity: Med…

    chrome · iphone os

    AI risk analysis on Exploit-DB.ai →

  9. UNSCOREDCVE-2026-101907public PoC

    Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter with maxRedirects set to zero and receives a redirect response. …

    AI risk analysis on Exploit-DB.ai →

  10. UNSCOREDCVE-2026-101905public PoC

    Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process prototype-pollution flaw places a …

    AI risk analysis on Exploit-DB.ai →

  11. UNSCOREDCVE-2026-61793public PoC

    Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults security.strict = false and security.secret = "" are used, and base64url-decodes the fo…

    AI risk analysis on Exploit-DB.ai →