CWE-359Base

Exposure of Private Personal Information to an Unauthorized Actor

Incomplete in the CWE catalog · 160 CVEs mapped

160
CVEs mapped
5.9
Median CVSS
What it is

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

Recent examples
3.1cvss
CVE-2026-21827

CVE-2026-21827 - LOW Severity Vulnerability

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data they are not entitled to, caused by improper handling of request data.

LOWno explanation yet
0%
epss
5.3cvss
CVE-2026-53497

CVE-2026-53497 - MEDIUM Severity Vulnerability

CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without authentication and returns the other_sessions array, which exposes metadata of all active sessions — including originating IP addresses, User-Agent strings, internal session IDs, and creation/expiry timestamps. Any unauthenticated network attacker can enumerate this data without credentials. Version 0.9.21 fixes the issue.

MEDIUMno explanation yet
0%
epss
7.5cvss
CVE-2026-74966

CVE-2026-74966 - HIGH Severity Vulnerability

Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-359
Abstraction
Base
Structure
Simple
Status
Incomplete
References (13)