CWE-204Base

Observable Response Discrepancy

Incomplete in the CWE catalog · 173 CVEs mapped

173
CVEs mapped
5.3
Median CVSS
What it is

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

Recent examples
7.5cvss
CVE-2026-19205

CVE-2026-19205 - HIGH Severity Vulnerability

Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting. This issue affects GastroMenum Web Panel: before 31.08.2026.

HIGHno explanation yet
0%
epss
7.5cvss
CVE-2026-19080

CVE-2026-19080 - HIGH Severity Vulnerability

Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448.

HIGHno explanation yet
0%
epss
4.3cvss
CVE-2026-78584

CVE-2026-78584 - MEDIUM Severity Vulnerability

Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-204
Abstraction
Base
Structure
Simple
Status
Incomplete