CWE-357Base

Insufficient UI Warning of Dangerous Operations

Draft in the CWE catalog · 20 CVEs mapped

20
CVEs mapped
5.3
Median CVSS
What it is

The user interface provides a warning to a user regarding dangerous or sensitive operations, but the warning is not noticeable enough to warrant attention.

Recent examples
4.3cvss
CVE-2026-58597

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

MEDIUMno explanation yet
1%
epss
4.6cvss
CVE-2026-47782

Android App "RoboForm Password Manager" provided by Siber Systems, Inc

Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web page is given through an intent, RoboForm may silently download files without user confirmation nor notification.

MEDIUMno explanation yet
0%
epss
7.1cvss
CVE-2026-26151

Remote Desktop Spoofing Vulnerability

Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network.

HIGHno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-357
Abstraction
Base
Structure
Simple
Status
Draft