CWE•Class•Incomplete•13 recent CVEs
CWE-923Improper Restriction of Communication Channel to Intended Endpoints
Description
The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.
[object Object]
Common consequences
- Integrity,Confidentiality→Gain Privileges or Assume IdentityIf an attacker can spoof the endpoint, the attacker gains all the privileges that were intended for the original endpoint.
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-239047.32026-07-29CVE-2026-632265.82026-07-23CVE-2026-89202026-07-15CVE-2026-598417.52026-07-14CVE-2026-570287.32026-07-09CVE-2026-338036.52026-07-09CVE-2026-556555.02026-06-23CVE-2026-125392026-06-18CVE-2026-120392026-06-18CVE-2025-361455.42026-05-26CVE-2026-227265.02026-05-01CVE-2025-361805.32026-04-30CVE-2025-628436.82026-03-20