Threadlinqs IntelligenceStart free

Weakness · ClassCWE-668

CWE-668: Exposure of Resource to Wrong Sphere

Class

As of 2026-10-05, CWE-668 (Exposure of Resource to Wrong Sphere) underlies 3 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 42 tracked threats.

CVEs
3Mapped to CWE-668
CISA KEV
0None listed yet
Critical
2CVSS v3 critical CVEs
Threats
42Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-668?

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Resources such as files and directories may be inadvertently exposed through mechanisms such as insecure permissions, or when a program accidentally operates on the wrong object. For example, a program may intend that private files can only be provided to a specific user. This effectively defines a control sphere that is intended to prevent attackers from accessing these private files. If the file permissions are insecure, then parties other than the user will be able to access those files. A separate control sphere might effectively require that the user can only access the private files, but not any other files on the system. If the program does not ensure that the user is only requesting private files, then the user might be able to access other files on the system. In either case, the end result is that a resource has been exposed to the wrong party.

CWE-668 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.

Source: MITRE CWE (CWE-668 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Confidentiality — Read Application Data. An adversary that gains access to a resource exposed to a wrong sphere could potentially retrieve private data from that resource, thus breaking the intended confidentiality of that data.
  • Integrity — Modify Application Data. An adversary that gains access to a resource exposed to a wrong sphere could potentially modify data held within that resource, thus breaking the intended integrity of that data and causing the system relying on that resource to make unintended decisions.
  • Other — Varies by Context. The consequences may vary widely depending on how the product uses the affected resource.

Source: MITRE CWE, common consequences.

How CWE-668 is exploited in the wild

Threadlinqs maps 3 CVEs to CWE-668, published between 2026-04-01 and 2026-08-13. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 2 critical, 1 high. The highest EPSS score in the set is 0.2% (CVE-2026-73843), the modelled probability of exploitation in the next 30 days. 42 tracked threats reference CWE-668 directly or through a CVE it covers; the most recent is “Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)” (2026-09-27). Affected products concentrate in Cisco (1), MervinPraison (1), openchoreo (1).

Vulnerabilities (CVEs)

All 3 CVEs mapped to CWE-668, CISA KEV first, then by CVSS score.

  • CVE-2026-20160 — CVSS 9.8 critical · EPSS 0.2% · published 2026-04-01
  • CVE-2026-73843 — CVSS 9.6 critical · EPSS 0.2% · published 2026-08-13
  • CVE-2026-44338 — CVSS 7.3 high · EPSS 0.0% · published 2026-05-08

Affected vendors

Threat activity

42 tracked threats cite CWE-668; the 25 most recent are listed.