CWE-283Base

Unverified Ownership

Draft in the CWE catalog · 26 CVEs mapped

26
CVEs mapped
6.4
Median CVSS
What it is

The product does not properly verify that a critical resource is owned by the proper entity.

Recent examples
8.7cvss
CVE-2026-85781

CVE-2026-85781 - HIGH Severity Vulnerability

Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion of directories on an EFS filesystem they are not authorized to access, via a crafted PersistentVolume volumeHandle that pairs an access point from one filesystem with a different target filesystem. To remediate this issue, users should upgrade to version v3.4.1.

HIGHno explanation yet
0%
epss
6.5cvss
CVE-2026-9745

CVE-2026-9745 - MEDIUM Severity Vulnerability

IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control.

MEDIUMno explanation yet
0%
epss
7.0cvss
CVE-2026-54467

CVE-2026-54467 - HIGH Severity Vulnerability

On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-283
Abstraction
Base
Structure
Simple
Status
Draft