CWE-669— Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.— MITRE CWE catalog
117 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-669page 3 of 3
- CVE-2026-44917MEDIUMCVSS 4.9EG 4.92026-06-04
OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
- CVE-2026-46447HIGHCVSS 7.7EG 7.72026-06-03
OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.
- CVE-2026-46448HIGHCVSS 8.5EG 8.52026-06-16
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.
- CVE-2026-48831HIGHCVSS 7.3EG 7.32026-05-24
Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some configurations, handling of an EXE file causes that file to be blindly executed with the permissions …
- CVE-2026-48845MEDIUMCVSS 6.5EG 6.52026-05-25
In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text…
- CVE-2026-48846MEDIUMCVSS 6.5EG 6.52026-05-25
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.
- CVE-2026-48847LOWCVSS 3.7EG 3.72026-05-25
Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.
- CVE-2026-71194MEDIUMCVSS 6.8EG 6.82026-08-12
In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic err…
- CVE-2026-73281LOWCVSS 3.5EG 3.52026-08-11
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@…
- CVE-2026-73574MEDIUMCVSS 6.5EG 6.52026-08-13
In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability b…
- CVE-2026-75000MEDIUMCVSS 5.8EG 5.82026-08-17
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.
- CVE-2026-75003CRITICALCVSS 9.8EG 9.82026-08-17
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.
- CVE-2026-75010MEDIUMCVSS 4.3EG 6.42026-08-17
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instan…
- CVE-2026-86144HIGHCVSS 7.8EG 7.82026-09-05
In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the …
- CVE-2026-87724MEDIUMCVSS 6.5EG 6.52026-09-09
Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.
- CVE-2026-89162LOWCVSS 3.3EG 3.32026-09-11
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
- CVE-2026-92952MEDIUMCVSS 6.8EG 6.82026-09-17
vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in lib/setup-sandbox.js and the cross-realm symbol checks and write traps in lib/bridge.js use a…
Map vulnerabilities like CWE-669 to your infrastructure
EchelonGraph correlates every CVE — across CWE-669 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →