CWE-494Base2 in KEV

Download of Code Without Integrity Check

Draft in the CWE catalog · 142 CVEs mapped

142
CVEs mapped
2
In KEV
7.8
Median CVSS
What it is

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

Recent examples
8.1cvss
CVE-2026-85427

CVE-2026-85427 - HIGH Severity Vulnerability

MOOS essential-moos pAntler through 10.0.1 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary programs by publishing a crafted MISSION_FILE message to the MOOSDB. Attackers can publish a mission file containing malicious Run entries that pAntler parses and executes via execvp() without authentication validation.

HIGHno explanation yet
0%
epss
5.4cvss
CVE-2026-84666

CVE-2026-84666 - MEDIUM Severity Vulnerability

Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage to an attacker-specified directory and modify history recording settings.

MEDIUMno explanation yet
0%
epss
5.4cvss
CVE-2026-84664

CVE-2026-84664 - MEDIUM Severity Vulnerability

Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL using GitLab API tokens already configured by administrators.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-494
Abstraction
Base
Structure
Simple
Status
Draft
References (8)