CWE-552— Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.— MITRE CWE catalog
526 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 11 of 11
- CVE-2026-57990HIGHCVSS 7.4EG 7.42026-07-26
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
- CVE-2026-59703HIGHCVSS 7.5EG 7.52026-07-08
repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to read arbitrary local git repositories. The isValidRemoteValue function in src/core/git/gitRemoteParse.ts fails to bloc…
- CVE-2026-63040HIGHCVSS 8.1EG 8.12026-08-20
Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. This issue affects Apache InLong: from 2…
- CVE-2026-63042HIGHCVSS 8.1EG 8.12026-08-20
Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data Node definitions. This issue affects Apache InLong: from 2.0.0 before 2.4.…
- CVE-2026-63490HIGHCVSS 7.5EG 7.52026-08-20
Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader wit…
- CVE-2026-6418MEDIUMCVSS 4.6EG 4.92026-05-05
An issue was discovered in the Shared Account Synchronization component of PaperCut MF (version 25.0.4). The application allows administrative users to configure a source path for account data synchronization. Due to a lack of proper pa…
- CVE-2026-67402CRITICALCVSS 9.2EG 9.22026-09-03
An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and …
- CVE-2026-68831MEDIUMCVSS 5.5EG 5.52026-09-08
Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.
- CVE-2026-73653CRITICALCVSS 9.4EG 9.42026-08-13
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept …
- CVE-2026-73705HIGHCVSS 8.8EG 8.82026-09-01
An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to ex…
- CVE-2026-73735MEDIUMCVSS 5.4EG 5.42026-09-01
Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to access some information beyond their privilege level. Successful exploitation could allow an attacker to obtain limite…
- CVE-2026-73736MEDIUMCVSS 5.3EG 5.32026-09-01
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affe…
- CVE-2026-74853MEDIUMCVSS 6.8EG 6.82026-09-04
The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root. Onl…
- CVE-2026-75164MEDIUMCVSS 6.5EG 6.52026-09-04
An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to retrieve arbitrary files from the device filesy…
- CVE-2026-75413HIGHCVSS 7.5EG 7.52026-08-26
DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any file via the parameter targetPath.
- CVE-2026-75464HIGHCVSS 8.1EG 8.12026-08-24
OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
- CVE-2026-75889HIGHCVSS 7.7EG 7.72026-08-27
Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file through bearerTokenFile. Alloy reads the file and sen…
- CVE-2026-76799MEDIUMCVSS 5.3EG 5.32026-08-20
A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the file /loginsystem/database/login_registration_system.sql of the component SQL Database Backup Handler. This manipulation…
- CVE-2026-77884HIGHCVSS 7.1EG 7.12026-09-14
Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.
- CVE-2026-78051MEDIUMCVSS 5.3EG 5.32026-08-22
A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the file /download/.metube/cookies.txt of the component Cookie File Handler. This manipulation causes files or directories a…
- CVE-2026-7817MEDIUMCVSS 6.5EG 6.52026-05-11
Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration endpoints. User-supplied api_key_file and api_url preferences were passed to the LLM provider clients without validation.…
- CVE-2026-80494HIGHCVSS 8.6EG 8.62026-09-12
The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download …
- CVE-2026-82020MEDIUMCVSS 6.8EG 6.82026-08-28
Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded the…
- CVE-2026-85175HIGHCVSS 8.8EG 8.82026-09-03
SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does not restrict the TLS private key (conf/ke…
- CVE-2026-8704MEDIUMCVSS 6.5EG 6.52026-05-15
Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified.
- CVE-2026-8715CRITICALCVSS 9.6EG 9.62026-08-13
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files f…
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →