CWE-489Base

Active Debug Code

Draft in the CWE catalog · 81 CVEs mapped

81
CVEs mapped
7.2
Median CVSS
What it is

The product is released with debugging code still enabled or active.

Recent examples
9.0cvss
CVE-2026-77545

CVE-2026-77545 - CRITICAL Severity Vulnerability

A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

CRITICALno explanation yet
0%
epss
5.4cvss
CVE-2026-66787

CVE-2026-66787 - MEDIUM Severity Vulnerability

A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-controlled IP addresses, causing other clusters' lighthouse DNS to redirect legitimate service traffic to malicious endpoints. This enables a remote attacker to conduct transparent Man-in-the-Middle (MITM) attacks on cross-cluster service communications, potentially leading to unauthorized information disclosure and data manipulation.

MEDIUMno explanation yet
0%
epss
8.8cvss
CVE-2026-66405

CVE-2026-66405 - HIGH Severity Vulnerability

DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-489
Abstraction
Base
Structure
Simple
Status
Draft
References (1)