What is CWE-346?
The product does not properly verify that the source of data or communication is valid.
CWE-346 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Not Technology-Specific; Technology: Web Based.
Source: MITRE CWE (CWE-346 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Access Control, Other — Gain Privileges or Assume Identity, Varies by Context. An attacker can access any functionality that is inadvertently accessible to the source.
Source: MITRE CWE, common consequences.
How CWE-346 is exploited in the wild
Threadlinqs maps 10 CVEs to CWE-346, published between 2025-12-05 and 2026-10-01. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 1 critical, 6 high, 2 medium. The highest EPSS score in the set is 35.3% (CVE-2025-34291), the modelled probability of exploitation in the next 30 days. 42 tracked threats reference CWE-346 directly or through a CVE it covers; the most recent is “Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features (CVE-2026-103922)” (2026-10-04). Affected products concentrate in Microsoft (3), @capacitor (1), Langflow (1), among 11 vendors in total.
Vulnerabilities (CVEs)
All 10 CVEs mapped to CWE-346, CISA KEV first, then by CVSS score.
- CVE-2025-34291 — CISA KEV · CVSS 8.8 high · EPSS 35.3% · published 2025-12-05
- CVE-2026-103922 — CVSS 9.3 critical · EPSS 0.2% · published 2026-10-01
- CVE-2026-66420 — CVSS 8.8 high · EPSS 0.1% · published 2026-07-30
- CVE-2026-59723 — CVSS 8.8 high · EPSS 0.1% · published 2026-07-08
- CVE-2026-84482 — CVSS 8.8 high · EPSS 0.1% · published 2026-09-01
- CVE-2026-56181 — CVSS 8.3 high · EPSS 0.2% · published 2026-07-14
- CVE-2026-57989 — CVSS 7.4 high · published 2026-07-26
- CVE-2026-91201 — CVSS 5.4 medium · EPSS 0.1% · published 2026-09-14
- CVE-2026-57978 — CVSS 5.4 medium · published 2026-07-26
- CVE-2026-15141 — published 2026-08-12
Affected vendors
Threat activity
42 tracked threats cite CWE-346; the 25 most recent are listed.
- Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features (CVE-2026-103922)CRITICAL
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit MalwareCRITICAL
- Bring Your Own EDR Attack Turns SentinelOne Into PPL-Protected Trojan Horse to Shield MalwareHIGH
- Origin-Validation Bypass in Connective (Nitro Software Belgium) eID Browser Extension Enables PIN Theft, Signature Forgery, and Drive-By RCE Across 2M+ Belgian UsersCRITICAL
- NatJack: NAT Connection-Tracking Manipulation Attacks Hijack TCP Sessions Across Windows, Linux, and macOS (CVE-2026-56181, CVE-2026-63913)HIGH
- OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI ApplicationsMEDIUM
- AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams Vishing (STAC4749), and Lumma Stealer Converge on the Legal SectorHIGH
- AWS CLI Login Phishing: Abusing `aws login --remote` Cross-Device Authentication to Steal Console/CLI SessionsHIGH
- CVE-2026-48294 ("HermeticReader"): Adobe Acrobat Chrome Extension Flaw Chain Enables Silent WhatsApp Web Data TheftHIGH
- Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass MFAHIGH
- CVE-2026-59208: Cross-Issuer Impersonation in n8n Enterprise Token ExchangeHIGH
- Kratos Phishing-as-a-Service Platform Targeting Microsoft 365 Users Across US and EuropeHIGH
- China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations Against Government, Supply-Chain, and Financial TargetsHIGH
- Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes, and 6,600 Monthly Social Media Scam Ads (Group-IB)HIGH
- Unpatched Claude for Chrome Extension Flaws Enable Unauthorized Account Actions via Fake Clicks and Permission BypassCRITICAL
- Misconfigured Server Exposes Three Evilginx-Based Microsoft 365 Phishing Operations (codemado, mail-argenta, saroula01)HIGH
- Forg365: Telegram-Distributed Phishing-as-a-Service Abusing Microsoft Device-Code Flow and AiTM to Hijack Microsoft 365/Entra SessionsHIGH
- CVE-2026-50746: Critical Unauthenticated Command Injection in Ubiquiti UniFi Connect Application (CVSS 10.0)CRITICAL
- Microsoft Exchange SSRF Vulnerability (CVE-2026-45504) — Public PoC Exploit Enables Authenticated Arbitrary File ReadHIGH
- Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member Stelios KouloglouHIGH
- Phantom Squatting: Attackers Register AI-Hallucinated Domains to Hijack LLM-Guided Traffic (Montana Empire / PhantomRaven)HIGH
- ARToken: Business Email Compromise-as-a-Service Platform Targeting Microsoft 365 (Cisco Talos / EvilTokens Affiliate)HIGH
- Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data ExfiltrationCRITICAL
- AutoJack: AutoGen Studio MCP WebSocket RCE Chain (localhost origin trust + unauthenticated /api/mcp endpoint + base64 server_params command injection)HIGH
- Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension Message-Validation Flaws Enable Zero-Interaction Browser Session Compromise Across 11M+ InstallsCRITICAL
Detection methods (MITRE CWE)
- Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.