CWE•Class•Draft•20 recent CVEs
CWE-610Externally Controlled Reference to a Resource in Another Sphere
Description
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
Common consequences
- Confidentiality,Integrity→Read Application Data,Modify Application DataAn adversary could read or modify data, depending on how the resource is intended to be used.
- Access Control→Gain Privileges or Assume IdentityAn adversary that can supply a reference to an unintended resource can potentially access a resource that they do not have privileges for, thus bypassing existing access control mechanisms.
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-553907.52026-07-28CVE-2026-553897.52026-07-28CVE-2026-155838.62026-07-15CVE-2026-128792026-07-09CVE-2026-108167.52026-06-30CVE-2026-573018.82026-06-24CVE-2026-127886.32026-06-21CVE-2026-476439.82026-06-09CVE-2026-04184.52026-06-09CVE-2026-457608.12026-05-21CVE-2026-473587.52026-05-19CVE-2026-473577.52026-05-19CVE-2026-309057.82026-05-13CVE-2026-411077.42026-05-12CVE-2026-343278.22026-05-07CVE-2026-308175.72026-04-08CVE-2026-308165.72026-04-08CVE-2026-05228.82026-04-01CVE-2026-309039.62026-03-11CVE-2026-34045.02026-03-02