CVE-2024-23683
Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of Invocati
CVSS
8.2
Alto
EPSS
0.4%
p29
KEV
—
Exploit Today
9
0-100
Publicado: 19 ene 2024 · Última mod.: 14 jul 2026 · CWE-653
0.4%EPSS · 30 días0.4%
2026-08-202026-09-17
Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code.
- github.comhttps://github.com/advisories/GHSA-883x-6fch-6wjx
- github.comhttps://github.com/ls1intum/Ares/commit/af4f28a56e2fe600d8750b3b415352a0a3217392
- github.comhttps://github.com/ls1intum/Ares/issues/15#issuecomment-996449371
- github.comhttps://github.com/ls1intum/Ares/releases/tag/1.7.6
- github.comhttps://github.com/ls1intum/Ares/security/advisories/GHSA-883x-6fch-6wjx
- vulncheck.comhttps://vulncheck.com/advisories/vc-advisory-GHSA-883x-6fch-6wjx
- github.comhttps://github.com/advisories/GHSA-883x-6fch-6wjx
- github.comhttps://github.com/ls1intum/Ares/commit/af4f28a56e2fe600d8750b3b415352a0a3217392
- github.comhttps://github.com/ls1intum/Ares/issues/15#issuecomment-996449371
- github.comhttps://github.com/ls1intum/Ares/releases/tag/1.7.6
- github.comhttps://github.com/ls1intum/Ares/security/advisories/GHSA-883x-6fch-6wjx
- vulncheck.comhttps://vulncheck.com/advisories/vc-advisory-GHSA-883x-6fch-6wjx
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-829648.8 ALT3.4%
——1Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM.
When the sandbox virtualizes a file it copies the original security descriptor, but the driver opened the virtualization target object with GENERIC_WRITE and FILE_WRITE_ATTRIBUTES only, omitting WRITE_DAC. Every attempt to apply the original DACL therefore failed, and the failure was discarded silently, leaving virtualized copies of sensitive files with permissive permissions. Because the IRP_MJ_CREATE callback additionally did not strip WRITE_DAC for sensitive directories, a sandboxed process could rewrite the security descriptor of a virtualized object, read the virtualized copy of the SAM database, extract local NTLM password hashes and execute code as SYSTEM.
The absence of an IRP_MJ_SET_SECURITY callback in the driver's operation registration table is a related defense-in-depth gap, but it is not the control that prevents this attack.1dCVE-2026-571357.6 ALT23.5%
——7PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment variables and does not establish an operating-system network boundary. Programs that ignore those proxy variables can open sockets directly, allowing supposedly isolated commands to reach localhost, internal services, cloud metadata, or external hosts and potentially exfiltrate data. An initial remediation was released in version 1.7.2.3dCVE-2026-15366—10.7%
——3A control logic defect in a specific built-in webpage of Kids Mode allows users to view local gallery photos directly within the page20dCVE-2026-713254.4 MED3.6%
——1Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.1dCVE-2026-622468.5 ALT19.2%
——6Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername(), allowing distinct tenants with colliding normalized identifiers to share control-plane state and read, modify, or destroy another tenant's Kubernetes data. This issue is fixed in version 26.7.4-edge.9dCVE-2026-65635—22.9%
——7Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attackers to register OpenID Connect clients with administrative privileges through the dynamic client registration entry point. Boruta.Openid.register_client/3 forwards caller-supplied registration parameters to the administrative client creation path without a public/admin field-level allowlist, so an unauthenticated registrant can set security-sensitive attributes including supported grant types, authorized scopes, PKCE enforcement, public refresh and revocation behavior, token lifetimes, and signing settings. The library does not distinguish between metadata a public registrant is allowed to set and administrative controls that should require operator approval.
This vulnerability is associated with program files lib/boruta/openid.ex and program routines 'Elixir.Boruta.Openid':register_client/3, 'Elixir.Boruta.Openid':parse_registration_params/2.
This issue affects boruta from 2.3.0 before 2.3.7.50d