Understand vulnerabilities and impacts

Last updated: June 25, 2026

Use this article when you see a vulnerability in Cysmiq and want to understand what it means, how serious it is, and what outcome it could have.

Vulnerability types

  • Secrets: leaked credentials, API keys, and tokens.
  • Code: security vulnerabilities in source code.
  • Dependencies: vulnerable packages flagged by advisory databases such as CVE and GHSA.

Severity

  • Critical: severe risk requiring immediate action.
  • High: significant risk that should be prioritized.
  • Medium: moderate risk to address in the normal workflow.
  • Low: minor risk to fix when convenient.

Impacts

Impacts describe the attacker outcome if a vulnerability is exploited. They help teams prioritize by business risk rather than only technical category.

  • Execute Commands: arbitrary code or command execution.
  • Takeover Accounts: account takeover, authentication bypass, or session hijacking.
  • Gain Access: authorization bypass or privilege escalation.
  • Obtain Secrets: credential, token, or key exposure.
  • Access Data: reading or changing structured data.

Canonical docs

For the maintained reference, see Vulnerabilities, Impacts, and Impact Reference.

Contact support if

  • You need help interpreting a vulnerability type, severity, or impact.
  • A vulnerability appears to have the wrong severity or impact category.
  • A finding is missing context that you expected to see.