Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-489

MITRE ↗

CWE-489

3
CRITICAL
7
HIGH
6
MEDIUM
17 CVEs
9.8
CVE-2026-49188

The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for u

9.1
CVE-2026-40035

Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mo

9.0
CVE-2026-77545

A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug

8.8
CVE-2026-58378

Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB a

8.8
CVE-2026-66405

DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to th

7.7
CVE-2026-9133

Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws

7.7
CVE-2026-59092

JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthentica

7.5
CVE-2026-45728

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path

7.5
CVE-2026-41186

When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components

7.5
CVE-2026-66403

DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log informatio

6.8
CVE-2026-33201

Digital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., LTD. contains an active debug code vulnerability. If this vul

6.7
CVE-2026-54799

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst

6.5
CVE-2026-58191

Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior

6.5
CVE-2026-54798

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst

5.5
CVE-2026-27131

The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior

5.3
CVE-2026-32662

Development and test API endpoints are present that mirror production functionality.

CVE-2026-65893

This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An atta

Frequently Asked Questions

What is CWE-489?

CWE-489 (CWE-489) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-489?

There are 17 CVE records associated with CWE-489 in our database. Of these, 3 are critical severity, 7 are high severity, and 6 are medium severity.

How can I protect against CWE-489 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-489 using AI-powered security agents.

Detect CWE-489 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-489 vulnerabilities across your infrastructure.

Get Started