What is CWE-352?
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
CWE-352 is a compound-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Language: Not Language-Specific; Technology: Web Based; Technology: Web Server.
Source: MITRE CWE (CWE-352 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Confidentiality, Integrity, Availability, Non-Repudiation, Access Control — Gain Privileges or Assume Identity, Bypass Protection Mechanism, Read Application Data, Modify Application Data, DoS: Crash, Exit, or Restart. The consequences will vary depending on the nature of the functionality that is vulnerable to CSRF. An attacker could trick a client into making an unintentional request to the web server via a URL, image load, XMLHttpRequest, etc., which would then be treated as an authentic request from the client - effectively performing any operations as the victim, leading to an exposure of data, unintended code execution, etc. If the victim is an administrator or privileged user, the consequences may…
Source: MITRE CWE, common consequences.
How CWE-352 is exploited in the wild
Threadlinqs maps 12 CVEs to CWE-352, published between 2008-09-18 and 2026-09-25. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 5 high, 6 medium. The highest EPSS score in the set is 12.0% (CVE-2008-4128), the modelled probability of exploitation in the next 30 days. 23 tracked threats reference CWE-352 directly or through a CVE it covers; the most recent is “Elementor Website Builder CSRF Flaw (CVE-2026-62062) Allows Attacker-Controlled WordPress Admin Account Creation (v4.3.0-4.3.1)” (2026-09-26). Affected products concentrate in Cisco (1), DevItems (1), Elementor (1), among 11 vendors in total.
Vulnerabilities (CVEs)
All 12 CVEs mapped to CWE-352, CISA KEV first, then by CVSS score.
- CVE-2025-62593 — CISA KEV · CVSS 8.8 high · EPSS 1.0% · published 2025-11-26
- CVE-2008-4128 — CISA KEV · CVSS 4.3 medium · EPSS 12.0% · published 2008-09-18
- CVE-2026-66602 — CVSS 8.8 high · EPSS 0.1% · published 2026-08-18
- CVE-2026-62062 — CVSS 8.8 high · EPSS 0.1% · published 2026-09-25
- CVE-2026-20296 — CVSS 8.3 high · published 2026-07-15
- CVE-2026-19650 — CVSS 7.1 high · published 2026-08-17
- CVE-2026-56024 — CVSS 6.5 medium · published 2026-06-18
- CVE-2026-82468 — CVSS 4.7 medium · published 2026-08-29
- CVE-2026-90599 — CVSS 4.3 medium · EPSS 0.1% · published 2026-09-13
- CVE-2026-18819 — CVSS 4.3 medium · EPSS 0.1% · published 2026-08-04
- CVE-2026-59520 — CVSS 4.3 medium · EPSS 0.1% · published 2026-07-05
- CVE-2026-58489 — EPSS 0.1% · published 2026-07-13
Affected vendors
Threat activity
23 tracked threats cite CWE-352:
- Elementor Website Builder CSRF Flaw (CVE-2026-62062) Allows Attacker-Controlled WordPress Admin Account Creation (v4.3.0-4.3.1)HIGH
- Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme InstallCRITICAL
- Click2Shell WordPress Exploit Chain Lets Attackers Gain RCE With a Single Malicious LinkCRITICAL
- CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability (CVE-2025-62593) by RondoDox BotnetCRITICAL
- NASA JPL AIT-GUI Missing Authentication and CSRF Flaw Allows Unauthenticated Spacecraft Command Injection (CVE-2026-60112, CVSS 9.8/9.4)CRITICAL
- Critical GitLab GraphQL Flaw (CVE-2026-19478, CVSS 9.4) Could Let Unauthenticated Attackers Delete Public ProjectsCRITICAL
- AI-Accelerated WordPress Plugin Vulnerability Research Surfaces 16 Unreported Bugs Across Dozens of PluginsHIGH
- WordPress Core XSS2Shell Vulnerability Chains Pre-Auth XSS to RCE (CVE-2026-64638)HIGH
- AgentForger: Cross-Site Agent Forgery in ChatGPT Workspace Agent BuilderCRITICAL
- Multiple Splunk Enterprise Vulnerabilities Enable Path Traversal and Information Disclosure (CVE-2026-20296, CVE-2026-20297, CVE-2026-20298)HIGH
- US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB Center 16 Router Exploitation via CVE-2018-0171/CVE-2008-4128)MEDIUM
- CVE-2008-4128 — Decades-Old Cisco IOS CSRF Vulnerability Added to CISA KEV After Active ExploitationHIGH
- FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171) Against RoutersCRITICAL
- CVE-2008-4128 Cisco IOS CSRF Vulnerability Added to CISA KEV — Exploited by Russian FSB Center 16 (Static Tundra / Berserk Bear) in Ongoing Router-Hygiene Espionage CampaignHIGH
- Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint NSA/FBI/13-Nation AdvisoryHIGH
- FSB Centre 16 (Berserk Bear/Energetic Bear) targets global critical national infrastructure via vulnerable routers — joint UK & allied advisoryHIGH
- phpBB Authentication Bypass and OAuth Account Takeover (CVE-2026-48611 / CVE-2026-48612) — Decade-Old Single-Request Login-as-Any-User Flaw, Fixed in 3.3.17CRITICAL
- 108 Malicious Chrome Extensions Steal OAuth Tokens, Hijack Telegram Sessions, and Deploy Backdoors via Shared C2 InfrastructureHIGH
- prt-scan: AI-Powered GitHub Actions Supply Chain Campaign Exploiting pull_request_targetHIGH
- Global Surge in HYIP (High-Yield Investment Platform) ScamsMEDIUM
- OpenClaw CVE-2026-25253: One-Click RCE via Token ExfiltrationHIGH
- ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social EngineeringCRITICAL
- Malicious Chrome Extensions: Affiliate Hijacking and ChatGPT Token Theft CampaignHIGH
Mitigations
- Architecture and Design / Libraries or Frameworks: Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. For example, use anti-CSRF packages such as the OWASP CSRFGuard. [REF-330] Another example is the ESAPI Session Management control, which includes a component for CSRF. [REF-45]
- Implementation: Ensure that the application is free of cross-site scripting issues (CWE-79), because most CSRF defenses can be bypassed using attacker-controlled script.
- Architecture and Design: Generate a unique nonce for each form, place the nonce into the form, and verify the nonce upon receipt of the form. Be sure that the nonce is not predictable (CWE-330). [REF-332]
- Architecture and Design: Identify especially dangerous operations. When the user performs a dangerous operation, send a separate confirmation request to ensure that the user intended to perform that operation.
- Architecture and Design: Use the "double-submitted cookie" method as described by Felten and Zeller: When a user visits a site, the site should generate a pseudorandom value and set it as a cookie on the user's machine. The site should require every form submission to include this value as a form value and also as a cookie value. When a POST request is sent to the site, the request should only be considered valid if the form value and the cookie value are the same. Because of the same-origin policy, an attacker cannot read or modify the value stored in the cookie. To successfully submit a form on behalf of the user, the attacker would have to correctly guess the pseudorandom value. If the pseudorandom value is…
- Architecture and Design: Do not use the GET method for any request that triggers a state change.
- Implementation: Check the HTTP Referer header to see if the request originated from an expected page. This could break legitimate functionality, because users or proxies may have disabled sending the Referer for privacy reasons.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Manual Analysis (effectiveness: High): This weakness can be detected using tools and techniques that require manual (human) analysis, such as penetration testing, threat modeling, and interactive tools that allow the tester to record and modify an active session. Specifically, manual analysis can be useful for finding this weakness, and for minimizing false positives assuming an understanding of business logic. However, it might not achieve desired code coverage within limited time constraints. For black-box analysis, if credentials…
- Automated Static Analysis (effectiveness: Limited): CSRF is currently difficult to detect reliably using automated techniques. This is because each application has its own implicit security policy that dictates which requests can be influenced by an outsider and automatically performed on behalf of a user, versus which requests require strong confidence that the user intends to make the request. For example, a keyword search of the public portion of a web site is typically expected to be encoded within a link that can be launched automatically…
- Automated Static Analysis - Binary or Bytecode (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Bytecode Weakness Analysis - including disassembler + source code weakness analysis Binary Weakness Analysis - including disassembler + source code weakness analysis
- Manual Static Analysis - Binary or Bytecode (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Binary / Bytecode disassembler - then use manual analysis for vulnerabilities & anomalies
- Dynamic Analysis with Automated Results Interpretation (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Web Application Scanner
- Dynamic Analysis with Manual Results Interpretation (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Fuzz Tester Framework-based Fuzzer
- Manual Static Analysis - Source Code (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Focused Manual Spotcheck - Focused manual analysis of source Manual Source Code Review (not inspections)
- Automated Static Analysis - Source Code (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Source code Weakness Analyzer Context-configured Source Code Weakness Analyzer
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.