Threadlinqs IntelligenceStart free

Weakness · ClassCWE-346

CWE-346: Origin Validation Error

KEV-linkedClass

As of 2026-10-05, CWE-346 (Origin Validation Error) underlies 10 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 42 tracked threats.

CVEs
10Mapped to CWE-346
CISA KEV
1Exploited in the wild
Critical
1CVSS v3 critical CVEs
Threats
42Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-346?

The product does not properly verify that the source of data or communication is valid.

CWE-346 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Not Technology-Specific; Technology: Web Based.

Source: MITRE CWE (CWE-346 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Access Control, Other — Gain Privileges or Assume Identity, Varies by Context. An attacker can access any functionality that is inadvertently accessible to the source.

Source: MITRE CWE, common consequences.

How CWE-346 is exploited in the wild

Threadlinqs maps 10 CVEs to CWE-346, published between 2025-12-05 and 2026-10-01. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 1 critical, 6 high, 2 medium. The highest EPSS score in the set is 35.3% (CVE-2025-34291), the modelled probability of exploitation in the next 30 days. 42 tracked threats reference CWE-346 directly or through a CVE it covers; the most recent is “Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features (CVE-2026-103922)” (2026-10-04). Affected products concentrate in Microsoft (3), @capacitor (1), Langflow (1), among 11 vendors in total.

Vulnerabilities (CVEs)

All 10 CVEs mapped to CWE-346, CISA KEV first, then by CVSS score.

Affected vendors

  • Microsoft — 3 CVEs
  • @capacitor — 1 CVE
  • Langflow — 1 CVE
  • TP-Link Systems Inc. — 1 CVE
  • WWBN — 1 CVE
  • Ylianst — 1 CVE
  • arc53 — 1 CVE
  • cline — 1 CVE
  • com.capacitorjs — 1 CVE
  • ionic-team — 1 CVE
  • swift — 1 CVE

Threat activity

42 tracked threats cite CWE-346; the 25 most recent are listed.

Detection methods (MITRE CWE)

  • Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.