CWE-351Base1 in KEV

Insufficient Type Distinction

Draft in the CWE catalog · 14 CVEs mapped

14
CVEs mapped
1
In KEV
6.6
Median CVSS
What it is

The product does not properly distinguish between different types of elements in a way that leads to insecure behavior.

Recent examples
none
CVE-2026-15305

CVE-2026-15305 - UNKNOWN Severity Vulnerability

Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. The restriction was not enforced server-side because the MimeTypeValidator was registered during form building before concrete form definition properties were applied, resulting in the validator never being added to the processing pipeline. This issue affects TYPO3 CMS versions 14.2.0-14.3.4.

no explanation yet
0%
epss
8.8cvss
CVE-2025-31951

HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability

HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that could permit unauthorized command execution.

HIGHno explanation yet
0%
epss
2.3cvss
CVE-2026-41341

OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extension

OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direct messages as direct messages in extensions/discord/src/monitor/agent-components-helpers.ts. Attackers can exploit this misclassification to bypass group DM policy enforcement or trigger incorrect session handling.

LOWno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-351
Abstraction
Base
Structure
Simple
Status
Draft