CWE-940Base1 in KEV

Improper Verification of Source of a Communication Channel

Incomplete in the CWE catalog · 46 CVEs mapped

46
CVEs mapped
1
In KEV
7.6
Median CVSS
What it is

The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.

Recent examples
9.6cvss
CVE-2026-85085

CVE-2026-85085 - CRITICAL Severity Vulnerability

The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.

CRITICALno explanation yet
0%
epss
8.8cvss
CVE-2026-78685

CVE-2026-78685 - HIGH Severity Vulnerability

Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Unauthenticated remote attackers can execute arbitrary OS commamnds via a crafted HTML page.

HIGHno explanation yet
0%
epss
6.8cvss
CVE-2026-73419

CVE-2026-73419 - MEDIUM Severity Vulnerability

NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On callback, a check value minted during a sign-in started with one provider can satisfy the callback for a different provider because the stored cookie is not verified against the callback provider's identity, including the provider ID, issuer, client ID, or redirect URI. In a multi-provider application that permits account linking while logged in, when one provider's authorization request is observable and a target provider callback can be satisfied without a PKCE verifier, an attacker can lure a victim into starting a legitimate same-origin flow and link the attacker's target-provider account to the victim's Auth.js user. The linked provider grants the attacker persistent sign-in to the victim's account, while cross-site request forgery alone is insufficient. This issue is fixed in @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-940
Abstraction
Base
Structure
Simple
Status
Incomplete
References (1)