CWE-441Class1 in KEV

Unintended Proxy or Intermediary ('Confused Deputy')

Draft in the CWE catalog · 85 CVEs mapped

85
CVEs mapped
1
In KEV
7.0
Median CVSS
What it is

The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.

Recent examples
5.0cvss
CVE-2026-86115

CVE-2026-86115 - MEDIUM Severity Vulnerability

Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens. Authenticated workflow authors can bypass external URL validation by supplying paths starting with /api/ in HTTP blocks to reach internal-only endpoints like POST /api/function/execute.

MEDIUMno explanation yet
0%
epss
5.3cvss
CVE-2026-84329

CVE-2026-84329 - MEDIUM Severity Vulnerability

Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

MEDIUMno explanation yet
0%
epss
10.0cvss
CVE-2026-83548

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

KEV · OVERDUECRITICALno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-441
Abstraction
Class
Structure
Simple
Status
Draft
References (2)