# CWE-345: Insufficient Verification of Data Authenticity

**KEV-linked**

> As of 2026-10-05, CWE-345 (Insufficient Verification of Data Authenticity) underlies 12 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 48 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-345?

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

CWE-345 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: ICS/OT.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/345.html) (CWE-345 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Integrity, Other** — Varies by Context, Unexpected State

_Source: MITRE CWE, common consequences._

## How CWE-345 is exploited in the wild

Threadlinqs maps 12 CVEs to CWE-345, published between 2023-08-23 and 2026-10-04. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 1 critical, 5 high, 6 medium. The highest EPSS score in the set is 93.8% (CVE-2023-38831), the modelled probability of exploitation in the next 30 days. 48 tracked threats reference CWE-345 directly or through a CVE it covers; the most recent is “Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse” (2026-09-25). Affected products concentrate in CoreWCF (3), AMD (1), Rarlab (1), among 10 vendors in total.

## Vulnerabilities (CVEs)

All 12 CVEs mapped to CWE-345, CISA KEV first, then by CVSS score.

- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831) — CISA KEV · CVSS 7.8 high · EPSS 93.8% · published 2023-08-23
- [CVE-2026-27510](https://intel.threadlinqs.com/cve/CVE-2026-27510) — CVSS 9.6 critical · EPSS 0.2% · published 2026-02-26
- [CVE-2023-20576](https://intel.threadlinqs.com/cve/CVE-2023-20576) — CVSS 7.7 high · EPSS 0.1% · published 2026-09-02
- [CVE-2026-54781](https://intel.threadlinqs.com/cve/CVE-2026-54781) — CVSS 7.4 high · EPSS 0.1% · published 2026-07-08
- [CVE-2026-54774](https://intel.threadlinqs.com/cve/CVE-2026-54774) — CVSS 7.4 high · EPSS 0.1% · published 2026-07-08
- [CVE-2026-54783](https://intel.threadlinqs.com/cve/CVE-2026-54783) — CVSS 7.4 high · EPSS 0.1% · published 2026-07-08
- [CVE-2026-73840](https://intel.threadlinqs.com/cve/CVE-2026-73840) — CVSS 5.3 medium · EPSS 0.2% · published 2026-08-13
- [CVE-2026-105161](https://intel.threadlinqs.com/cve/CVE-2026-105161) — CVSS 5.3 medium · published 2026-10-04
- [CVE-2026-44434](https://intel.threadlinqs.com/cve/CVE-2026-44434) — CVSS 5.3 medium · published 2026-07-16
- [CVE-2026-9242](https://intel.threadlinqs.com/cve/CVE-2026-9242) — CVSS 5.3 medium · published 2026-06-27
- [CVE-2026-13507](https://intel.threadlinqs.com/cve/CVE-2026-13507) — CVSS 5 medium · EPSS 0.1% · published 2026-06-28
- [CVE-2026-73657](https://intel.threadlinqs.com/cve/CVE-2026-73657) — CVSS 4.2 medium · EPSS 0.1% · published 2026-08-13

## Affected vendors

- [CoreWCF](https://intel.threadlinqs.com/vendors/corewcf) — 3 CVEs
- **AMD** — 1 CVE
- **Rarlab** — 1 CVE
- **UnitreeRobotics** — 1 CVE
- [h2o](https://intel.threadlinqs.com/vendors/h2o) — 1 CVE
- **invariant-systems-ai** — 1 CVE
- **metagauss** — 1 CVE
- [openchoreo](https://intel.threadlinqs.com/vendors/openchoreo) — 1 CVE
- **triggerdotdev** — 1 CVE
- **volcengine** — 1 CVE

## Threat activity

48 tracked threats cite CWE-345; the 25 most recent are listed.

- [Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse](https://intel.threadlinqs.com/threat/TL-2026-2650) — CRITICAL · 2026-09-25
- [Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing Flaws Across Azure and Copilot AI Products, Plus a Windows Secure Kernel EoP (CVE-2026-85921)](https://intel.threadlinqs.com/threat/TL-2026-2563) — CRITICAL · 2026-09-18
- [JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnet](https://intel.threadlinqs.com/threat/TL-2026-2111) — HIGH · 2026-08-22
- [Visa Kernel 3 EMV Protocol Flaw — Zombie Card Relay Attack Enables Expired Contactless Card Purchases](https://intel.threadlinqs.com/threat/TL-2026-2102) — HIGH · 2026-08-21
- [Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimi](https://intel.threadlinqs.com/threat/TL-2026-2056) — HIGH · 2026-08-18
- [Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage Campaign Against Europe's Ukraine Defence Supply Chain](https://intel.threadlinqs.com/threat/TL-2026-2031) — HIGH · 2026-08-16
- [Bring Your Own EDR Attack Turns SentinelOne Into PPL-Protected Trojan Horse to Shield Malware](https://intel.threadlinqs.com/threat/TL-2026-2017) — HIGH · 2026-08-14
- [RovoBlast: One-Click Parameter-to-Prompt Injection in Atlassian Rovo AI Exposes Confluence, Jira, and SharePoint Data](https://intel.threadlinqs.com/threat/TL-2026-1942) — CRITICAL · 2026-08-08
- [OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI Applications](https://intel.threadlinqs.com/threat/TL-2026-1913) — MEDIUM · 2026-08-06
- [CVE-2026-17583 — High-Severity Tampering Flaw in Thermo Fisher Applied Biosystems Forensic DNA Analysis Software](https://intel.threadlinqs.com/threat/TL-2026-1854) — HIGH · 2026-08-04
- [US FCC Bans Imported Advanced Robots Over Supply-Chain Risk and UniPwn-Class Takeover Vulnerabilities (CVE-2025-35027)](https://intel.threadlinqs.com/threat/TL-2026-1751) — HIGH · 2026-07-29
- [Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled](https://intel.threadlinqs.com/threat/TL-2026-1721) — HIGH · 2026-07-27
- [Multiple Notepad++ Vulnerabilities Enable PowerShell Command Injection, Stack Buffer Overflow, and Zip Slip Path Traversal (CVE-2026-52886, CVE-2026-54758, CVE-2026-57233)](https://intel.threadlinqs.com/threat/TL-2026-1348) — MEDIUM · 2026-07-15
- [Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)](https://intel.threadlinqs.com/threat/TL-2026-1298) — HIGH · 2026-07-14
- [Microsoft July 2026 Patch Tuesday: Record 622 Flaws Fixed, Two Zero-Days Under Active Exploitation (CVE-2026-56164, CVE-2026-56155)](https://intel.threadlinqs.com/threat/TL-2026-1334) — CRITICAL · 2026-07-14
- [Multi-Actor Espionage Campaign Weaponizes Balochistan Police Complaint Management Portal (PlugX, ShadowPad, Cobalt Strike, Remcos/TAG-179)](https://intel.threadlinqs.com/threat/TL-2026-1239) — HIGH · 2026-07-11
- [HalluSquatting: AI Coding Assistant Hallucinations Weaponized to Deliver Botnet Malware via Fake Package/Tool/Skill Names](https://intel.threadlinqs.com/threat/TL-2026-1164) — MEDIUM · 2026-07-10
- [GNU Guix 'guix substitute' and 'guix pull' Vulnerabilities Enable Arbitrary File Write, Metadata Spoofing, Local Secret Disclosure, and Path Traversal (CVE Pending)](https://intel.threadlinqs.com/threat/TL-2026-1179) — HIGH · 2026-07-10
- [Indirect Prompt Injection via Web Content Targets AI Agents (SEO Poisoning + Payment Scam / Typosquat Campaigns)](https://intel.threadlinqs.com/threat/TL-2026-1087) — MEDIUM · 2026-07-02
- [Cordyceps: Systemic Cross-Workflow Privilege-Escalation Supply-Chain Flaw in GitHub Actions CI/CD Pipelines (Microsoft Azure Sentinel, Google ADK, Apache Doris, Cloudflare Workers SDK, PSF Black)](https://intel.threadlinqs.com/threat/TL-2026-0928) — CRITICAL · 2026-06-23
- [Google Cloud Vertex AI Python SDK Bucket-Squatting ("Pickle in the Middle") Enables Cross-Tenant Model Hijacking and RCE](https://intel.threadlinqs.com/threat/TL-2026-0880) — HIGH · 2026-06-19
- [Pickle in the Middle: Vertex AI Model Upload Hijacking via GCS Bucket Squatting Enables Cross-Tenant RCE (google-cloud-aiplatform v1.139.0/v1.140.0)](https://intel.threadlinqs.com/threat/TL-2026-0825) — HIGH · 2026-06-16
- [Maine AG Data Breach Notification Portal Abused to Publish Fraudulent Breach Disclosures Impersonating VRChat and Discord](https://intel.threadlinqs.com/threat/TL-2026-0792) — MEDIUM · 2026-06-14
- [OceanLotus (APT32) Supply-Chain Compromise of FireAnt MetaKit Delivers SPECTRALVIPER Backdoor to Vietnamese Stock Investors](https://intel.threadlinqs.com/threat/TL-2026-0795) — HIGH · 2026-06-14
- [CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic Flaw Enables Unprivileged Local Root via cifs.upcall Namespace Hijack (Public PoC, CVE Pending)](https://intel.threadlinqs.com/threat/TL-2026-0618) — HIGH · 2026-05-28

## Detection methods (MITRE CWE)

- **Automated Static Analysis** (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-693 Protection Mechanism Failure](https://intel.threadlinqs.com/cwe/CWE-693)

Canonical: https://intel.threadlinqs.com/cwe/CWE-345
Source definition: https://cwe.mitre.org/data/definitions/345.html
Detection rules and IOCs for threats exploiting CWE-345 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
