CWE•Base•Draft•14 recent CVEs
CWE-283Unverified Ownership
Description
The product does not properly verify that a critical resource is owned by the proper entity.
Common consequences
- Access Control→Gain Privileges or Assume IdentityAn attacker could gain unauthorized access to system resources.
Potential mitigations
- Architecture and Design,OperationVery carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
- Architecture and DesignConsider following the principle of separation of privilege. Require multiple conditions to be met before permitting access to a system resource.
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-879135.92026-09-10CVE-2026-879125.92026-09-10CVE-2026-843865.12026-09-08CVE-2026-857818.72026-09-04CVE-2026-97456.52026-09-03CVE-2026-544677.02026-08-26CVE-2026-155993.32026-08-06CVE-2026-447076.82026-05-26CVE-2026-445626.52026-05-15CVE-2026-403375.12026-04-18CVE-2026-42697.52026-03-16CVE-2026-05984.22026-02-06CVE-2026-209129.12026-01-22CVE-2020-85546.32021-01-21