CWE-471Base

Modification of Assumed-Immutable Data (MAID)

Draft in the CWE catalog · 36 CVEs mapped

36
CVEs mapped
6.3
Median CVSS
What it is

The product does not properly protect an assumed-immutable element from being modified by an attacker.

Recent examples
5.4cvss
CVE-2026-84664

CVE-2026-84664 - MEDIUM Severity Vulnerability

Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL using GitLab API tokens already configured by administrators.

MEDIUMno explanation yet
0%
epss
3.1cvss
CVE-2026-59299

CVE-2026-59299 - LOW Severity Vulnerability

Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier

LOWno explanation yet
0%
epss
9.9cvss
CVE-2026-50481

CVE-2026-50481 - CRITICAL Severity Vulnerability

Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

CRITICALno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-471
Abstraction
Base
Structure
Simple
Status
Draft