CWE-706Class

Use of Incorrectly-Resolved Name or Reference

Incomplete in the CWE catalog · 69 CVEs mapped

69
CVEs mapped
6.0
Median CVSS
What it is

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

Recent examples
4.3cvss
CVE-2026-79273

CVE-2026-79273 - MEDIUM Severity Vulnerability

Incorrect reference resolution in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

MEDIUMno explanation yet
0%
epss
4.3cvss
CVE-2026-79264

CVE-2026-79264 - MEDIUM Severity Vulnerability

Incorrect reference resolution in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

MEDIUMno explanation yet
0%
epss
4.3cvss
CVE-2026-79254

CVE-2026-79254 - MEDIUM Severity Vulnerability

Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-706
Abstraction
Class
Structure
Simple
Status
Incomplete