CWE-923Class

Improper Restriction of Communication Channel to Intended Endpoints

Incomplete in the CWE catalog · 63 CVEs mapped

63
CVEs mapped
6.9
Median CVSS
What it is

The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.

Recent examples
8.7cvss
CVE-2026-62836

CVE-2026-62836 - HIGH Severity Vulnerability

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.

HIGHno explanation yet
0%
epss
6.5cvss
CVE-2026-18655

CVE-2026-18655 - MEDIUM Severity Vulnerability

Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context. To remediate this issue, users should upgrade to version 2.0.24.

MEDIUMno explanation yet
0%
epss
7.3cvss
CVE-2026-23904

CVE-2026-23904 - HIGH Severity Vulnerability

Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, resulting in SSRF or open-proxy behavior. This issue affects Apache Kyuubi: from 1.8.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which disables the proxy by default. To restore proxied Engine UI, set kyuubi.frontend.rest.engine.ui.proxy.enabled=true and configure allowed target hosts with kyuubi.frontend.rest.engine.ui.proxy.hosts.

HIGHno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-923
Abstraction
Class
Structure
Simple
Status
Incomplete