CWE-669Class

Incorrect Resource Transfer Between Spheres

Draft in the CWE catalog · 64 CVEs mapped

64
CVEs mapped
5.4
Median CVSS
What it is

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Recent examples
5.6cvss
CVE-2026-86144

CVE-2026-86144 - MEDIUM Severity Vulnerability

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).

MEDIUMno explanation yet
0%
epss
6.4cvss
CVE-2026-75010

CVE-2026-75010 - MEDIUM Severity Vulnerability

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.

MEDIUMno explanation yet
0%
epss
5.8cvss
CVE-2026-75003

CVE-2026-75003 - MEDIUM Severity Vulnerability

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-669
Abstraction
Class
Structure
Simple
Status
Draft