What is CWE-669?
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
CWE-669 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.
Source: MITRE CWE (CWE-669 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Confidentiality, Integrity — Read Application Data, Modify Application Data, Unexpected State
Source: MITRE CWE, common consequences.
How CWE-669 is exploited in the wild
Threadlinqs maps 6 CVEs to CWE-669, published between 2026-02-01 and 2026-08-12. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 2 high, 3 medium, 1 low. The highest EPSS score in the set is 3.9% (CVE-2026-31431), the modelled probability of exploitation in the next 30 days. 10 tracked threats reference CWE-669 directly or through a CVE it covers; the most recent is “Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)” (2026-09-23). Affected products concentrate in Roundcube (3), Linux (1), OpenStack (1), among 4 vendors in total.
Vulnerabilities (CVEs)
All 6 CVEs mapped to CWE-669, CISA KEV first, then by CVSS score.
- CVE-2026-31431 — CISA KEV · CVSS 7.8 high · EPSS 3.9% · published 2026-04-22
- CVE-2026-25253 — CVSS 8.8 high · EPSS 0.0% · published 2026-02-01
- CVE-2026-71194 — CVSS 6.8 medium · EPSS 0.5% · published 2026-08-12
- CVE-2026-48845 — CVSS 6.5 medium · EPSS 0.0% · published 2026-05-25
- CVE-2026-48846 — CVSS 6.5 medium · EPSS 0.0% · published 2026-05-25
- CVE-2026-48847 — CVSS 3.7 low · EPSS 0.0% · published 2026-05-25
Affected vendors
Threat activity
10 tracked threats cite CWE-669:
- Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)CRITICAL
- CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of DisclosureHIGH
- ClawHub Marketplace Skills Expose OpenClaw AI Agents to RCE, Data Theft, and Supply-Chain Backdoors (CVE-2026-25253)HIGH
- Linux Kernel LPE Surge: Copy Fail (CVE-2026-31431), Dirty Frag/Fragnesia (CVE-2026-43284/CVE-2026-43500/CVE-2026-46300), and CrackArmor AppArmor Flaws vs. Defense-in-Depth MitigationsHIGH
- Roundcube Webmail Pre-Auth SQL Injection in virtuser_query Plugin (CVE-2026-48842) — Patched in 1.6.16 / 1.7.1 Alongside 7 Other VulnerabilitiesHIGH
- CVE-2026-31431 "Copy Fail" — Linux Kernel algif_aead Deterministic Local Privilege Escalation Affecting All Major DistributionsHIGH
- Linux Kernel 'Copy Fail' Local Privilege Escalation (CVE-2026-31431) — algif_aead 4-Byte Page Cache Write to setuid RootHIGH
- CVE-2026-25253: OpenClaw One-Click RCE via Malicious LinkCRITICAL
- OpenClaw AI Agent Framework Security Concerns Prompt Detection ToolingMEDIUM
- OpenClaw CVE-2026-25253: One-Click RCE via Token ExfiltrationHIGH