CWE-552

CWE-552 · 3 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-552, highest CVSS first.

  1. HIGH 7.7CVE-2026-77259public PoC

    MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment opens a caller-selected server-local file without checking that the resolved path remains in the workspace. A cal…

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 6.2CVE-2026-6544

    IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.

    concert · linux kernel

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.2CVE-2026-15915

    IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.

    AI risk analysis on Exploit-DB.ai →