CWE-706

Use of Incorrectly-Resolved Name or Reference
AI Translation Available

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

Status
incomplete
Abstraction
class

Common Consequences

confidentiality integrity
Impacts
read application data modify application data

Detection Methods

automated static analysis

Potential Mitigations