CWE-552Base1 in KEV

Files or Directories Accessible to External Parties

Draft in the CWE catalog · 276 CVEs mapped

276
CVEs mapped
1
In KEV
7.1
Median CVSS
What it is

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Recent examples
6.5cvss
CVE-2026-75164

CVE-2026-75164 - MEDIUM Severity Vulnerability

An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to retrieve arbitrary files from the device filesystem via the file query string parameter.

MEDIUMno explanation yet
0%
epss
6.8cvss
CVE-2026-74853

CVE-2026-74853 - MEDIUM Severity Vulnerability

The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.

MEDIUMno explanation yet
0%
epss
none
CVE-2026-67402

CVE-2026-67402 - UNKNOWN Severity Vulnerability

An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31.

no explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-552
Abstraction
Base
Structure
Simple
Status
Draft
References (2)