The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.
Volume of CVEs assigned to CWE-653 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
69 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1974CRITICAL A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the | Mar 25, 2025 | 9.8 | 92 | NO | YES |
CVE-2025-21590MEDIUM An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of t | Mar 12, 2025 | 4.4 | 56 | YES | NO |
CVE-2026-26956CRITICAL vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host | May 4, 2026 | 9.8 | 45 | NO | NO |
CVE-2026-26332CRITICAL vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in | May 4, 2026 | 10.0 | 42 | NO | NO |
CVE-2026-24781CRITICAL vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to writ | May 4, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-53421CRITICAL Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements can achieve remote code execution through the connector s | Jul 20, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-53405CRITICAL Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST | Jul 20, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-63071CRITICAL Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements for Implementations can create a malicious Groovy class con | Jul 20, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-44005CRITICAL vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes i | May 13, 2026 | 10.0 | 40 | NO | NO |
CVE-2026-43997CRITICAL vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one e | May 13, 2026 | 10.0 | 40 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.