CWE•Class•Draft•20 recent CVEs
CWE-610Externally Controlled Reference to a Resource in Another Sphere
Description
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
Common consequences
- Confidentiality,Integrity→Read Application Data,Modify Application DataAn adversary could read or modify data, depending on how the resource is intended to be used.
- Access Control→Gain Privileges or Assume IdentityAn adversary that can supply a reference to an unintended resource can potentially access a resource that they do not have privileges for, thus bypassing existing access control mechanisms.
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-190325.32026-09-01CVE-2026-218104.42026-08-26CVE-2026-792568.32026-08-25CVE-2026-789664.32026-08-25CVE-2026-629607.42026-08-21CVE-2026-765724.72026-08-19CVE-2026-685626.22026-07-30CVE-2026-553907.52026-07-28CVE-2026-553897.52026-07-28CVE-2026-155838.62026-07-15CVE-2026-128792026-07-09CVE-2026-108167.52026-06-30CVE-2026-573018.82026-06-24CVE-2026-127886.32026-06-21CVE-2026-476439.82026-06-09CVE-2026-04184.52026-06-09CVE-2026-457608.12026-05-21CVE-2026-473587.52026-05-19CVE-2026-473577.52026-05-19CVE-2026-309057.82026-05-13