CWE-653Class1 in KEV

Improper Isolation or Compartmentalization

Draft in the CWE catalog · 56 CVEs mapped

56
CVEs mapped
1
In KEV
6.6
Median CVSS
What it is

The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

Recent examples
none
CVE-2026-15366

CVE-2026-15366 - UNKNOWN Severity Vulnerability

A control logic defect in a specific built-in webpage of Kids Mode allows users to view local gallery photos directly within the page

no explanation yet
0%
epss
none
CVE-2026-71325

CVE-2026-71325 - UNKNOWN Severity Vulnerability

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.

no explanation yet
0%
epss
8.5cvss
CVE-2026-62246

CVE-2026-62246 - HIGH Severity Vulnerability

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername(), allowing distinct tenants with colliding normalized identifiers to share control-plane state and read, modify, or destroy another tenant's Kubernetes data. This issue is fixed in version 26.7.4-edge.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-653
Abstraction
Class
Structure
Simple
Status
Draft
References (4)