Understand vulnerabilities and impacts
Last updated: June 25, 2026
Use this article when you see a vulnerability in Cysmiq and want to understand what it means, how serious it is, and what outcome it could have.
Vulnerability types
- Secrets: leaked credentials, API keys, and tokens.
- Code: security vulnerabilities in source code.
- Dependencies: vulnerable packages flagged by advisory databases such as CVE and GHSA.
Severity
- Critical: severe risk requiring immediate action.
- High: significant risk that should be prioritized.
- Medium: moderate risk to address in the normal workflow.
- Low: minor risk to fix when convenient.
Impacts
Impacts describe the attacker outcome if a vulnerability is exploited. They help teams prioritize by business risk rather than only technical category.
- Execute Commands: arbitrary code or command execution.
- Takeover Accounts: account takeover, authentication bypass, or session hijacking.
- Gain Access: authorization bypass or privilege escalation.
- Obtain Secrets: credential, token, or key exposure.
- Access Data: reading or changing structured data.
Canonical docs
For the maintained reference, see Vulnerabilities, Impacts, and Impact Reference.
Contact support if
- You need help interpreting a vulnerability type, severity, or impact.
- A vulnerability appears to have the wrong severity or impact category.
- A finding is missing context that you expected to see.