# CWE-346: Origin Validation Error

**KEV-linked**

> As of 2026-10-05, CWE-346 (Origin Validation Error) underlies 10 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 42 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-346?

The product does not properly verify that the source of data or communication is valid.

CWE-346 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Not Technology-Specific; Technology: Web Based.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/346.html) (CWE-346 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Access Control, Other** — Gain Privileges or Assume Identity, Varies by Context. An attacker can access any functionality that is inadvertently accessible to the source.

_Source: MITRE CWE, common consequences._

## How CWE-346 is exploited in the wild

Threadlinqs maps 10 CVEs to CWE-346, published between 2025-12-05 and 2026-10-01. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 1 critical, 6 high, 2 medium. The highest EPSS score in the set is 35.3% (CVE-2025-34291), the modelled probability of exploitation in the next 30 days. 42 tracked threats reference CWE-346 directly or through a CVE it covers; the most recent is “Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features (CVE-2026-103922)” (2026-10-04). Affected products concentrate in Microsoft (3), @capacitor (1), Langflow (1), among 11 vendors in total.

## Vulnerabilities (CVEs)

All 10 CVEs mapped to CWE-346, CISA KEV first, then by CVSS score.

- [CVE-2025-34291](https://intel.threadlinqs.com/cve/CVE-2025-34291) — CISA KEV · CVSS 8.8 high · EPSS 35.3% · published 2025-12-05
- [CVE-2026-103922](https://intel.threadlinqs.com/cve/CVE-2026-103922) — CVSS 9.3 critical · EPSS 0.2% · published 2026-10-01
- [CVE-2026-66420](https://intel.threadlinqs.com/cve/CVE-2026-66420) — CVSS 8.8 high · EPSS 0.1% · published 2026-07-30
- [CVE-2026-59723](https://intel.threadlinqs.com/cve/CVE-2026-59723) — CVSS 8.8 high · EPSS 0.1% · published 2026-07-08
- [CVE-2026-84482](https://intel.threadlinqs.com/cve/CVE-2026-84482) — CVSS 8.8 high · EPSS 0.1% · published 2026-09-01
- [CVE-2026-56181](https://intel.threadlinqs.com/cve/CVE-2026-56181) — CVSS 8.3 high · EPSS 0.2% · published 2026-07-14
- [CVE-2026-57989](https://intel.threadlinqs.com/cve/CVE-2026-57989) — CVSS 7.4 high · published 2026-07-26
- [CVE-2026-91201](https://intel.threadlinqs.com/cve/CVE-2026-91201) — CVSS 5.4 medium · EPSS 0.1% · published 2026-09-14
- [CVE-2026-57978](https://intel.threadlinqs.com/cve/CVE-2026-57978) — CVSS 5.4 medium · published 2026-07-26
- [CVE-2026-15141](https://intel.threadlinqs.com/cve/CVE-2026-15141) — published 2026-08-12

## Affected vendors

- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 3 CVEs
- **@capacitor** — 1 CVE
- **Langflow** — 1 CVE
- **TP-Link Systems Inc.** — 1 CVE
- [WWBN](https://intel.threadlinqs.com/vendors/wwbn) — 1 CVE
- **Ylianst** — 1 CVE
- **arc53** — 1 CVE
- **cline** — 1 CVE
- **com.capacitorjs** — 1 CVE
- **ionic-team** — 1 CVE
- **swift** — 1 CVE

## Threat activity

42 tracked threats cite CWE-346; the 25 most recent are listed.

- [Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features (CVE-2026-103922)](https://intel.threadlinqs.com/threat/TL-2026-2894) — CRITICAL · 2026-10-04
- [CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malware](https://intel.threadlinqs.com/threat/TL-2026-2474) — CRITICAL · 2026-09-13
- [Bring Your Own EDR Attack Turns SentinelOne Into PPL-Protected Trojan Horse to Shield Malware](https://intel.threadlinqs.com/threat/TL-2026-2017) — HIGH · 2026-08-14
- [Origin-Validation Bypass in Connective (Nitro Software Belgium) eID Browser Extension Enables PIN Theft, Signature Forgery, and Drive-By RCE Across 2M+ Belgian Users](https://intel.threadlinqs.com/threat/TL-2026-1967) — CRITICAL · 2026-08-10
- [NatJack: NAT Connection-Tracking Manipulation Attacks Hijack TCP Sessions Across Windows, Linux, and macOS (CVE-2026-56181, CVE-2026-63913)](https://intel.threadlinqs.com/threat/TL-2026-1927) — HIGH · 2026-08-07
- [OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI Applications](https://intel.threadlinqs.com/threat/TL-2026-1913) — MEDIUM · 2026-08-06
- [AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams Vishing (STAC4749), and Lumma Stealer Converge on the Legal Sector](https://intel.threadlinqs.com/threat/TL-2026-1777) — HIGH · 2026-07-30
- [AWS CLI Login Phishing: Abusing `aws login --remote` Cross-Device Authentication to Steal Console/CLI Sessions](https://intel.threadlinqs.com/threat/TL-2026-1646) — HIGH · 2026-07-23
- [CVE-2026-48294 ("HermeticReader"): Adobe Acrobat Chrome Extension Flaw Chain Enables Silent WhatsApp Web Data Theft](https://intel.threadlinqs.com/threat/TL-2026-1637) — HIGH · 2026-07-22
- [Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass MFA](https://intel.threadlinqs.com/threat/TL-2026-1584) — HIGH · 2026-07-21
- [CVE-2026-59208: Cross-Issuer Impersonation in n8n Enterprise Token Exchange](https://intel.threadlinqs.com/threat/TL-2026-1436) — HIGH · 2026-07-17
- [Kratos Phishing-as-a-Service Platform Targeting Microsoft 365 Users Across US and Europe](https://intel.threadlinqs.com/threat/TL-2026-1408) — HIGH · 2026-07-16
- [China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations Against Government, Supply-Chain, and Financial Targets](https://intel.threadlinqs.com/threat/TL-2026-1354) — HIGH · 2026-07-15
- [Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes, and 6,600 Monthly Social Media Scam Ads (Group-IB)](https://intel.threadlinqs.com/threat/TL-2026-1313) — HIGH · 2026-07-14
- [Unpatched Claude for Chrome Extension Flaws Enable Unauthorized Account Actions via Fake Clicks and Permission Bypass](https://intel.threadlinqs.com/threat/TL-2026-1318) — CRITICAL · 2026-07-14
- [Misconfigured Server Exposes Three Evilginx-Based Microsoft 365 Phishing Operations (codemado, mail-argenta, saroula01)](https://intel.threadlinqs.com/threat/TL-2026-1258) — HIGH · 2026-07-13
- [Forg365: Telegram-Distributed Phishing-as-a-Service Abusing Microsoft Device-Code Flow and AiTM to Hijack Microsoft 365/Entra Sessions](https://intel.threadlinqs.com/threat/TL-2026-1202) — HIGH · 2026-07-11
- [CVE-2026-50746: Critical Unauthenticated Command Injection in Ubiquiti UniFi Connect Application (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1159) — CRITICAL · 2026-07-10
- [Microsoft Exchange SSRF Vulnerability (CVE-2026-45504) — Public PoC Exploit Enables Authenticated Arbitrary File Read](https://intel.threadlinqs.com/threat/TL-2026-1113) — HIGH · 2026-07-05
- [Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member Stelios Kouloglou](https://intel.threadlinqs.com/threat/TL-2026-1098) — HIGH · 2026-07-03
- [Phantom Squatting: Attackers Register AI-Hallucinated Domains to Hijack LLM-Guided Traffic (Montana Empire / PhantomRaven)](https://intel.threadlinqs.com/threat/TL-2026-1031) — HIGH · 2026-07-01
- [ARToken: Business Email Compromise-as-a-Service Platform Targeting Microsoft 365 (Cisco Talos / EvilTokens Affiliate)](https://intel.threadlinqs.com/threat/TL-2026-1036) — HIGH · 2026-07-01
- [Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-0976) — CRITICAL · 2026-06-28
- [AutoJack: AutoGen Studio MCP WebSocket RCE Chain (localhost origin trust + unauthenticated /api/mcp endpoint + base64 server_params command injection)](https://intel.threadlinqs.com/threat/TL-2026-0904) — HIGH · 2026-06-22
- [Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension Message-Validation Flaws Enable Zero-Interaction Browser Session Compromise Across 11M+ Installs](https://intel.threadlinqs.com/threat/TL-2026-0870) — CRITICAL · 2026-06-19

## Detection methods (MITRE CWE)

- **Automated Static Analysis**: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-345 Insufficient Verification of Data Authenticity](https://intel.threadlinqs.com/cwe/CWE-345)
- [CWE-284 Improper Access Control](https://intel.threadlinqs.com/cwe/CWE-284)

Canonical: https://intel.threadlinqs.com/cwe/CWE-346
Source definition: https://cwe.mitre.org/data/definitions/346.html
Detection rules and IOCs for threats exploiting CWE-346 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
