CVE-2026-1220
published 2026-06-10CVE-2026-1220: Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security…
PriorityP342high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
0.30%
21.5th percentile
Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | chromium | < chromium 144.0.7559.96-1~deb12u1 (bookworm) | chromium 144.0.7559.96-1~deb12u1 (bookworm) |
| chrome | < 144.0.7559.99 | 144.0.7559.99 | |
| chrome | >= 144.0.7559.99 < 144.0.7559.99 | 144.0.7559.99 | |
| chrome_chrome | — | — | |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
cisa7.8HIGH
vendor_redhat9.1CRITICAL
vendor_cisco5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 144.0.7559.59 V8 race condition (EUVD-2026-36108 / Nessus ID 294789)
vuldb·2026-06-11·CVSS 7.5
CVE-2026-1220 [HIGH] Google Chrome up to 144.0.7559.59 V8 race condition (EUVD-2026-36108 / Nessus ID 294789)
A vulnerability has been found in Google Chrome and classified as problematic. Impacted is an unknown function of the component V8. The manipulation leads to race condition.
This vulnerability is traded as CVE-2026-1220. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
GHSA
Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page.
ghsa_unreviewed·2026-06-10
CVE-2026-1220 [HIGH] CWE-362 Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page.
Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)
GHSA
Keycloak Account Resources user lookup contains broken access control
ghsa·2026-05-19
CVE-2026-37981 [MEDIUM] CWE-1220 Keycloak Account Resources user lookup contains broken access control
Keycloak Account Resources user lookup contains broken access control
Keycloak's Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile objects for unrelated users. This leads to broad profile-level information disclosure.
GHSA
Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record
ghsa·2026-04-24
CVE-2026-38743 [MEDIUM] CWE-1220 Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record
Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record
The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance records: a logged-in Airflow user with read access to at least one DAG could retrieve HITL prompts (including their request parameters) and full TaskInstance details for DAGs outside their authorized scope. Because HITL prompts and TaskInstance fields routinely carry operator parameters and free-form context attached to a task, the leak widens visibility of DAG-run data beyond the intended per-DAG RBAC boundary for every authenticated user.
Users are recommended to upgrade to version 3.2.1 , which fixes this issue.
GHSA
Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions
ghsa·2026-04-24
CVE-2026-40690 [MEDIUM] CWE-1220 Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions
Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions
The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asset in the deployment and learn the existence and names of DAGs and assets outside their authorized scope.
Users are recommended to upgrade to version 3.2.1, which fixes this issue.
Red Hat
openstack-ironic: Prevent rehoming resources to nodes with different owner
vendor_redhat·2026-07-08·CVSS 8.7
CVE-2026-44918 [HIGH] CWE-1220 openstack-ironic: Prevent rehoming resources to nodes with different owner
openstack-ironic: Prevent rehoming resources to nodes with different owner
A flaw was found in OpenStack Ironic. An authenticated project manager can change the node associated with Volume Connectors or Volume Target objects, potentially changing the project permitted to access the object. Volume Connectors contain secrets in environments configuring boot from volume with iSCSI volumes. Additionally, a project manager with the ability to create nodes can use the UUID of a node not owned by their project as a parent node when creating a new node. This mismatched child node can then be used to impact operations on the parent, such as forcing it to power on.
Statement: The Red Hat Product Security team has assessed the severity of this vulnerability as Important. An authenticated project ma
Red Hat
keycloak-services: keycloak: FGAP v2 parent group children endpoint bypasses per-child view permission filter
vendor_redhat·2026-07-03·CVSS 4.3
CVE-2026-14615 [MEDIUM] CWE-1220 keycloak-services: keycloak: FGAP v2 parent group children endpoint bypasses per-child view permission filter
keycloak-services: keycloak: FGAP v2 parent group children endpoint bypasses per-child view permission filter
A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissions when requested through a parent group. This allows a delegated administrator to view details of child groups they are not authorized to access directly, including group names, paths, and custom attributes.
Statement: The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that it requires the attacker to possess a delegated administrator role with specific permissions. Successful exploitation allows
Red Hat
ImageMagick: ImageMagick: Unauthorized file access due to missing policy checks in concatenate operation
vendor_redhat·2026-07-01·CVSS 5.5
CVE-2026-55628 [MEDIUM] CWE-1220 ImageMagick: ImageMagick: Unauthorized file access due to missing policy checks in concatenate operation
ImageMagick: ImageMagick: Unauthorized file access due to missing policy checks in concatenate operation
In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. This issue has been fixed in version 7.1.2-26.
A flaw was found in ImageMagick. The `-concatenate` operation, used for combining images, lacks proper security policy checks. This oversight could allow an attacker to read from or write to file paths that should otherwise be restricted by the security policy. This could lead to unauthorized access to sensitive system resources.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Se
Red Hat
org.apache.activemq/activemq-broker: org.apache.activemq/activemq-all: org.apache.activemq/activemq: Apache ActiveMQ: Information disclosure due to broken temporary destination isolation
vendor_redhat·2026-06-30·CVSS 7.5
CVE-2026-54475 [HIGH] CWE-1220 org.apache.activemq/activemq-broker: org.apache.activemq/activemq-all: org.apache.activemq/activemq: Apache ActiveMQ: Information disclosure due to broken temporary destination isolation
org.apache.activemq/activemq-broker: org.apache.activemq/activemq-all: org.apache.activemq/activemq: Apache ActiveMQ: Information disclosure due to broken temporary destination isolation
A flaw was found in Apache ActiveMQ. Temporary destinations, which are designed to be private to a specific connection, can be accessed by other connections due to a missing authorization check. This allows an unauthorized connection to consume messages from another connection's temporary destination, leading to information disclosure.
Statement: Red Hat products ship Apache ActiveMQ Classic components as transitive dependencies. The vulnerability is in the Classic ActiveMQ broker's temporary destination isolation, where access control is enforced only client-side, allowing a different connection to cons
Red Hat
jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application
vendor_redhat·2026-06-23·CVSS 5.3
CVE-2026-54517 [MEDIUM] CWE-1220 jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application
jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter was applied only to creator properties; the regular property-buffering branch performed no prop.visibleInView(activeView) check. A change making SetterlessProperty.isMerging() return true routed setterless Collection/Map properties through this unguarded path, so a setterless collection annotated with a restricted @JsonView is populated from attacker JSON even when the active view excludes it. This vulnerability is fixed in 2.21.4 and 3.1.4.
A flaw was fo
Red Hat
litellm: Litellm: Improper authorization vulnerability
vendor_redhat·2026-06-21·CVSS 7.5
CVE-2026-12771 [HIGH] CWE-1220 litellm: Litellm: Improper authorization vulnerability
litellm: Litellm: Improper authorization vulnerability
A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulation leads to improper authorization. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is reported as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
A flaw was found in BerriAI litellm. A remote attacker can exploit an improper authorization vulnerability within the M2M JWT Handler. This could allow unauthorized access, leading to a low impact on the confidentiality, integrity, and availability of affected res
Red Hat
kernel: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible
vendor_redhat·2026-06-19·CVSS 7.0
CVE-2026-52908 [HIGH] CWE-1220 kernel: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible
kernel: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible
In the Linux kernel, the following vulnerability has been resolved:
RDMA: During rereg_mr ensure that REREG_ACCESS is compatible
If IB_MR_REREG_ACCESS changes from RO to RW then the umem has to be
re-evaluated to ensure it is properly pinned as RW. Since the umem is
hidden inside each driver's mr struct add a ib_umem_check_rereg() function
that each driver has to call before processing IB_MR_REREG_ACCESS.
mlx4 has to retain its duplicate ib_access_writable check because it
implements IB_MR_REREG_ACCESS | IB_MR_REREG_TRANS by changing both items
in place sequentially while the MR is live, so it will continue to not
support this combination.
A flaw was found in the Linux kernel. This vulnerability occurs during the re-reg
Red Hat
ChromaDB: ChromaDB: Unauthorized cross-tenant actions due to improper authorization checks
vendor_redhat·2026-06-12·CVSS 8.8
CVE-2026-45831 [HIGH] CWE-1220 ChromaDB: ChromaDB: Unauthorized cross-tenant actions due to improper authorization checks
ChromaDB: ChromaDB: Unauthorized cross-tenant actions due to improper authorization checks
The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.
A flaw was found in the SimpleRBACAuthorizationProvider authorization provider in the ChromaDB Python project. This vulnerability allows an authenticated user to perform actions across different tenants, databases, or collections without proper authorization. The provider incorrectly evaluates user permissions without verifying the specific scope (tenant, database, or collection) to which those permissions
Red Hat
chromium-browser: chromium-browser: Race in V8
vendor_redhat·2026-06-10·CVSS 7.5
CVE-2026-1220 [HIGH] CWE-843 chromium-browser: chromium-browser: Race in V8
chromium-browser: chromium-browser: Race in V8
Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)
A race flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=473851441
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
keycloak: Keycloak: Information disclosure due to user profile permission bypass
vendor_redhat·2026-06-05·CVSS 2.7
CVE-2026-9088 [LOW] CWE-1220 keycloak: Keycloak: Information disclosure due to user profile permission bypass
keycloak: Keycloak: Information disclosure due to user profile permission bypass
A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.
Statement: Low: A flaw in Keycloak allows administrators with delegated access to read group memberships and users to bypass user profile permissions. This enables the viewing of user attributes that are configured to be denied, impacting data confidentiality for specific administrative roles.
Mitigation: Mitigation for this issue is either not available or the currently available opt
Red Hat
chromium-browser: Inappropriate implementation in Browser
vendor_redhat·2026-06-02·CVSS 4.3
CVE-2026-11257 [MEDIUM] CWE-1220 chromium-browser: Inappropriate implementation in Browser
chromium-browser: Inappropriate implementation in Browser
Inappropriate implementation in Browser in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
An inappropriate implementation flaw was found in the Browser component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=499051898
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
activemq: Apache ActiveMQ: Denial of Service via incomplete authorization
vendor_redhat·2026-06-01·CVSS 4.3
CVE-2026-46605 [MEDIUM] CWE-1220 activemq: Apache ActiveMQ: Denial of Service via incomplete authorization
activemq: Apache ActiveMQ: Denial of Service via incomplete authorization
Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions.
This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.
Users are recommended to upgrade to version v6.2.6 or v5.19.7, which fixes the issue.
A flaw was found in Apache ActiveMQ server. An authenticated attacker with proper permissions could exploit an incomplete authorization vulnerability to remove existing destinations. This could lead to a Denial of Service (DoS) by disrupting message delivery an
Red Hat
kernel: net: libwx: fix VF illegal register access
vendor_redhat·2026-05-28
CVE-2026-46142 CWE-1220 kernel: net: libwx: fix VF illegal register access
kernel: net: libwx: fix VF illegal register access
A flaw was found in the Linux kernel's `libwx` network driver. When a Virtual Function (VF) is initialized, it attempts to read a Physical Function (PF) restricted register, `WX_CFG_PORT_ST`. This illegal register access can lead to a system hang, resulting in a Denial of Service (DoS).
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red H
Red Hat
github.com/mlflow/mlflow: MLflow: Arbitrary code execution via unauthorized multipart upload access
vendor_redhat·2026-05-25·CVSS 9.0
CVE-2026-2651 [CRITICAL] CWE-1220 github.com/mlflow/mlflow: MLflow: Arbitrary code execution via unauthorized multipart upload access
github.com/mlflow/mlflow: MLflow: Arbitrary code execution via unauthorized multipart upload access
A flaw was found in MLflow when the `--serve-artifacts` mode is enabled. A remote attacker can exploit this vulnerability due to insufficient resource-level permission checks for multipart upload (MPU) endpoints. This allows the attacker to overwrite artifacts belonging to other users, which can lead to model supply chain poisoning and potentially arbitrary code execution when compromised models are loaded.
Statement: No Red Hat products ship affected versions of mlflow.
Package: rhoai/odh-mlflow-rhel9 (Red Hat OpenShift AI (RHOAI)) - Not affected
Package: rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9 (Red Hat OpenShift AI (RHOAI)) - Not affected
Package: rhoai/odh-pipeline-run
Red Hat
keycloak: org.keycloak.authorization: Keycloak: Information disclosure via broken access control in user lookup endpoint
vendor_redhat·2026-05-19·CVSS 4.3
CVE-2026-37981 [MEDIUM] CWE-1220 keycloak: org.keycloak.authorization: Keycloak: Information disclosure via broken access control in user lookup endpoint
keycloak: org.keycloak.authorization: Keycloak: Information disclosure via broken access control in user lookup endpoint
A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By sending crafted requests with arbitrary usernames or email values, the endpoint returns full profile objects for unrelated users. This leads to broad profile-level information disclosure.
Statement: Moderate: This vulnerability in Red Hat Build of Keycloak (RHBK) allows an authenticated user to bypass access controls in the Account Resources user lookup endpoint. By sending c
Red Hat
chromium-browser: chromium-browser: Insufficient policy enforcement in Payments
vendor_redhat·2026-05-14·CVSS 4.3
CVE-2026-8566 [MEDIUM] CWE-1220 chromium-browser: chromium-browser: Insufficient policy enforcement in Payments
chromium-browser: chromium-browser: Insufficient policy enforcement in Payments
Insufficient policy enforcement in Payments in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)
An insufficient policy enforcement flaw was found in the Payments component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=470646792
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
grafana: Grafana: Unauthorized annotation deletion by editor users
vendor_redhat·2026-05-13·CVSS 4.3
CVE-2026-28374 [MEDIUM] CWE-1220 grafana: Grafana: Unauthorized annotation deletion by editor users
grafana: Grafana: Unauthorized annotation deletion by editor users
A flaw was found in Grafana. An authenticated editor user could exploit this vulnerability to delete any annotation, even those for which they lack read permissions. This unauthorized action compromises the integrity of data by allowing deletion of information beyond their intended access scope.
Package: multicluster-globalhub/multicluster-globalhub-grafana-rhel9 (Multicluster Global Hub) - Fix deferred
Package: rhacm2/acm-grafana-rhel9 (Red Hat Advanced Cluster Management for Kubernetes 2) - Fix deferred
Package: rhceph/rhceph-5-dashboard-rhel8 (Red Hat Ceph Storage 5) - Not affected
Package: rhceph/rhceph-6-dashboard-rhel9 (Red Hat Ceph Storage 6) - Not affected
Package: rhceph/grafana-rhel9 (Red Hat Ceph Storage 8)
Red Hat
kernel: nsfs: tighten permission checks for handle opening
vendor_redhat·2026-05-08
CVE-2026-43391 CWE-1220 kernel: nsfs: tighten permission checks for handle opening
kernel: nsfs: tighten permission checks for handle opening
A flaw was found in the Linux kernel's nsfs component. This vulnerability allows privileged services to potentially view the namespaces of other privileged services, leading to information disclosure. This could enable unauthorized access to sensitive data or configurations between isolated services.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Pac
Red Hat
Spring Cloud Config: Spring Cloud Config: Information disclosure of secrets from unintended GCP projects
vendor_redhat·2026-05-07·CVSS 7.5
CVE-2026-40981 [HIGH] CWE-1220 Spring Cloud Config: Spring Cloud Config: Information disclosure of secrets from unintended GCP projects
Spring Cloud Config: Spring Cloud Config: Information disclosure of secrets from unintended GCP projects
When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Clo
Red Hat
chromium-browser: Insufficient policy enforcement in DirectSockets
vendor_redhat·2026-05-05·CVSS 7.3
CVE-2026-7962 [MEDIUM] CWE-1220 chromium-browser: Insufficient policy enforcement in DirectSockets
chromium-browser: Insufficient policy enforcement in DirectSockets
An insufficient policy enforcement flaw was found in the DirectSockets component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=497081987
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
axios: Axios: Information disclosure due to `no_proxy` bypass
vendor_redhat·2026-04-24·CVSS 6.8
CVE-2026-42038 [MEDIUM] CWE-1220 axios: Axios: Information disclosure due to `no_proxy` bypass
axios: Axios: Information disclosure due to `no_proxy` bypass
A flaw was found in Axios, a software library used for making web requests. This vulnerability allows an attacker to bypass the `no_proxy` configuration, which is designed to prevent certain internal network requests from being sent through an external proxy. Specifically, when `no_proxy=localhost` is set, requests intended for local system addresses (such as 127.0.0.1 and [::1]) are still routed through the proxy. This could lead to unintended exposure of internal network traffic or sensitive information.
Mitigation: To mitigate this issue, explicitly include `127.0.0.1` and `[::1]` in the `no_proxy` environment variable or application-specific proxy bypass configuration. This ensures that requests to these loopback addresses
CISA
Microsoft Defender Insufficient Granularity of Access Control Vulnerability
cisa·2026-04-22·CVSS 7.8
CVE-2026-33825 [HIGH] CWE-1220 Microsoft Defender Insufficient Granularity of Access Control Vulnerability
Vulnerability: Microsoft Defender Insufficient Granularity of Access Control Vulnerability
Affected: Microsoft Defender
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825 ; https://nvd.nist.gov/vuln/detail/CVE-2026-33825
Remediation Due Date: 2026-05-06
Red Hat
kata-containers: Arbitrary file write inside guest image via CopyFile policy
vendor_redhat·2026-04-22·CVSS 8.2
CVE-2026-41326 [HIGH] CWE-1220 kata-containers: Arbitrary file write inside guest image via CopyFile policy
kata-containers: Arbitrary file write inside guest image via CopyFile policy
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers; even those running inside CVMs. This vulnerability is fixed in v3.29.0.
A flaw was found in Kata Containers. An oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite
Red Hat
argocd-image-updater: ArgoCD Image Updater: Cross-Namespace Privilege Escalation via insufficient namespace validation
vendor_redhat·2026-04-15·CVSS 9.1
CVE-2026-6388 [CRITICAL] CWE-1220 argocd-image-updater: ArgoCD Image Updater: Cross-Namespace Privilege Escalation via insufficient namespace validation
argocd-image-updater: ArgoCD Image Updater: Cross-Namespace Privilege Escalation via insufficient namespace validation
A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting insufficient validation, the attacker can trigger unauthorized image updates on applications managed by other tenants. This leads to cross-namespace privilege escalation, impacting application integrity through unauthorized application updates.
Statement: Critical: A cross-namespace privilege escalation flaw in Argo CD Image Updater, a component of Red Hat OpenShift GitOps, allows an attacker with permissions to create or modify `ImageUpdater` resources t
Red Hat
Vite: Vite: Information disclosure via WebSocket connection bypasses access control
vendor_redhat·2026-04-07·CVSS 8.2
CVE-2026-39363 [HIGH] CWE-1220 Vite: Vite: Information disclosure via WebSocket connection bypasses access control
Vite: Vite: Information disclosure via WebSocket connection bypasses access control
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default "..."). The access control enforced in the HTTP request path (such as server.fs.allow) is not applied to this WebSocket-based execution path. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.
A flaw was found in Vite, a frontend tooling framework. A remote attacker can exploit this vulnerabi
Red Hat
kernel: drm/xe: Open-code GGTT MMIO access protection
vendor_redhat·2026-04-03·CVSS 5.5
CVE-2026-23466 [MEDIUM] CWE-1220 kernel: drm/xe: Open-code GGTT MMIO access protection
kernel: drm/xe: Open-code GGTT MMIO access protection
In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Open-code GGTT MMIO access protection
GGTT MMIO access is currently protected by hotplug (drm_dev_enter),
which works correctly when the driver loads successfully and is later
unbound or unloaded. However, if driver load fails, this protection is
insufficient because drm_dev_unplug() is never called.
Additionally, devm release functions cannot guarantee that all BOs with
GGTT mappings are destroyed before the GGTT MMIO region is removed, as
some BOs may be freed asynchronously by worker threads.
To address this, introduce an open-coded flag, protected by the GGTT
lock, that guards GGTT MMIO access. The flag is cleared during the
dev_fini_ggtt devm release funct
Red Hat
github.com/nats-io/nats-server: NATS-Server: Unauthorized trace message redirection via message tracing headers
vendor_redhat·2026-03-25·CVSS 4.3
CVE-2026-33249 [MEDIUM] CWE-1220 github.com/nats-io/nats-server: NATS-Server: Unauthorized trace message redirection via message tracing headers
github.com/nats-io/nats-server: NATS-Server: Unauthorized trace message redirection via message tracing headers
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.11.0 and prior to versions 2.11.15 and 2.12.6, a valid client which uses message tracing headers can indicate that the trace messages can be sent to an arbitrary valid subject, including those to which the client does not have publish permission. The payload is a valid trace message and not chosen by the attacker. Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds are available.
A flaw was found in NATS-Server. A valid client can exploit this flaw by manipulating message tracing headers to redirect trace messages to any valid subject, even those for
Red Hat
Kibana: Kibana: Unauthorized system control via missing authorization
vendor_redhat·2026-03-19·CVSS 6.5
CVE-2026-26939 [MEDIUM] CWE-1220 Kibana: Kibana: Unauthorized system control via missing authorization
Kibana: Kibana: Unauthorized system control via missing authorization
Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Response Action Configuration (host isolation, process termination, and process suspension) via CAPEC-1 (Accessing Functionality Not Properly Constrained by ACLs). This requires an authenticated attacker with rule management privileges.
A flaw was found in Kibana. An authenticated attacker with rule management privileges could exploit a missing authorization vulnerability in the server-side Detection Rule Management. This allows the attacker to configure unauthorized endpoint response actions, such as host isolation, process termination, and process suspension. This could lead to a denial of service or im
Cisco
Cisco Application Policy Infrastructure Controller Denial of Service Vulnerability
vendor_cisco·2026-02-25·CVSS 5.5
CVE-2026-20107 [MEDIUM] CWE-1220 Cisco Application Policy Infrastructure Controller Denial of Service Vulnerability
Cisco Application Policy Infrastructure Controller Denial of Service Vulnerability
A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. To exploit this vulnerability, the attacker must have valid user credentials and any role that includes CLI access.
This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by issuing crafted commands at the CLI prompt. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Cisco has released software updates that address this vulnerability. There are no
Red Hat
vaultwarden: Vaultwarden: Information disclosure due to bypassed collection permissions
vendor_redhat·2026-02-11·CVSS 6.5
CVE-2026-26012 [MEDIUM] CWE-1220 vaultwarden: Vaultwarden: Information disclosure due to bypassed collection permissions
vaultwarden: Vaultwarden: Information disclosure due to bypassed collection permissions
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to 1.35.3, a regular organization member can retrieve all ciphers within an organization, regardless of collection permissions. The endpoint /ciphers/organization-details is accessible to any organization member and internally uses Cipher::find_by_org to retrieve all ciphers. These ciphers are returned with CipherSyncType::Organization without enforcing collection-level access control. This vulnerability is fixed in 1.35.3.
A flaw was found in vaultwarden, an unofficial Bitwarden compatible server. A regular organization member can retrieve all ciphers (encrypted data) within an organization
Red Hat
github.com/openfga/openfga: OpenFGA Improper Policy Enforcement
vendor_redhat·2026-02-06·CVSS 5.8
CVE-2026-24851 [MEDIUM] CWE-1220 github.com/openfga/openfga: OpenFGA Improper Policy Enforcement
github.com/openfga/openfga: OpenFGA Improper Policy Enforcement
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.5 to v1.11.2 ( openfga-0.2.22<= Helm chart <= openfga-0.2.51, v.1.8.5 <= docker <= v.1.11.2) are vulnerable to improper policy enforcement when certain Check calls are executed. The vulnerability requires a model that has a a relation directly assignable by a type bound public access and assignable by type bound non-public access, a tuple assigned for the relation that is a type bound public access, a tuple assigned for the same object with the same relation that is not type bound public access, and a tuple assigned for a different object that has an object ID lexicographically larger w
Chrome
Stable Channel Update for Desktop: CVE-2026-1220
vendor_chrome·2026-01-20
CVE-2026-1220 [HIGH] Stable Channel Update for Desktop: CVE-2026-1220
Stable Channel Update for Desktop
CVE-2026-1220: Race in V8. Reported by @p1nky4745 on 2026-01-07 We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel
Severity: high
Microsoft
Chromium: CVE-2026-1220 Race in V8
vendor_msrc·2026-01-13
CVE-2026-1220 Chromium: CVE-2026-1220 Race in V8
Chromium: CVE-2026-1220 Race in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
144.0.3719.92
01/23/2026
144.0.7559.96/.97
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microso
Debian
CVE-2026-1220: chromium
vendor_debian·2026
CVE-2026-1220 CVE-2026-1220: chromium
bookworm: resolved (fixed in 144.0.7559.96-1~deb12u1)
bullseye: open
forky: resolved (fixed in 144.0.7559.96-1)
sid: resolved (fixed in 144.0.7559.96-1)
trixie: resolved (fixed in 144.0.7559.96-1~deb13u1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-1220 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2026-1220 CVE-2026-1220 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1220 :
vulnerability analysis and mitigation
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Source : NVD
Published January 23, 2026
CNA Score N/A
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cef
chromium-headless-debuginfo
Sources
NVD
Alpine 3.23 Has Fix Added at: Feb 01, 2026
Alpine edge Has Fix Added at: Jan 31, 2026
Debian 11 No Fix Added at: Jan 22, 2026
Debian 12, 13, 14 Has Fix Added at: Jan 22, 2026
Echo Has Fix Added at: Jan 21, 2026
## Get a CVE risk assessmen
Bugzilla
CVE-2026-1220 chromium: chromium-browser: Race in V8 [epel-all]
bugzilla·2026-06-22·CVSS 7.5
CVE-2026-1220 [HIGH] CVE-2026-1220 chromium: chromium-browser: Race in V8 [epel-all]
CVE-2026-1220 chromium: chromium-browser: Race in V8 [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
It's fixed in 149.0.7827.155
Bugzilla
CVE-2026-1220 chromium: chromium-browser: Race in V8 [fedora-all]
bugzilla·2026-06-22·CVSS 7.5
CVE-2026-1220 [HIGH] CVE-2026-1220 chromium: chromium-browser: Race in V8 [fedora-all]
CVE-2026-1220 chromium: chromium-browser: Race in V8 [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
It's fixed in 149.0.7827.155
Bugzilla
CVE-2026-1220 chromium-browser: chromium-browser: Race in V8
bugzilla·2026-06-10·CVSS 7.5
CVE-2026-1220 [HIGH] CVE-2026-1220 chromium-browser: chromium-browser: Race in V8
CVE-2026-1220 chromium-browser: chromium-browser: Race in V8
Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)
2026-06-10
Published