# CWE-669: Incorrect Resource Transfer Between Spheres

**KEV-linked**

> As of 2026-10-05, CWE-669 (Incorrect Resource Transfer Between Spheres) underlies 6 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 10 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-669?

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

CWE-669 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/669.html) (CWE-669 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Confidentiality, Integrity** — Read Application Data, Modify Application Data, Unexpected State

_Source: MITRE CWE, common consequences._

## How CWE-669 is exploited in the wild

Threadlinqs maps 6 CVEs to CWE-669, published between 2026-02-01 and 2026-08-12. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 2 high, 3 medium, 1 low. The highest EPSS score in the set is 3.9% (CVE-2026-31431), the modelled probability of exploitation in the next 30 days. 10 tracked threats reference CWE-669 directly or through a CVE it covers; the most recent is “Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)” (2026-09-23). Affected products concentrate in Roundcube (3), Linux (1), OpenStack (1), among 4 vendors in total.

## Vulnerabilities (CVEs)

All 6 CVEs mapped to CWE-669, CISA KEV first, then by CVSS score.

- [CVE-2026-31431](https://intel.threadlinqs.com/cve/CVE-2026-31431) — CISA KEV · CVSS 7.8 high · EPSS 3.9% · published 2026-04-22
- [CVE-2026-25253](https://intel.threadlinqs.com/cve/CVE-2026-25253) — CVSS 8.8 high · EPSS 0.0% · published 2026-02-01
- [CVE-2026-71194](https://intel.threadlinqs.com/cve/CVE-2026-71194) — CVSS 6.8 medium · EPSS 0.5% · published 2026-08-12
- [CVE-2026-48845](https://intel.threadlinqs.com/cve/CVE-2026-48845) — CVSS 6.5 medium · EPSS 0.0% · published 2026-05-25
- [CVE-2026-48846](https://intel.threadlinqs.com/cve/CVE-2026-48846) — CVSS 6.5 medium · EPSS 0.0% · published 2026-05-25
- [CVE-2026-48847](https://intel.threadlinqs.com/cve/CVE-2026-48847) — CVSS 3.7 low · EPSS 0.0% · published 2026-05-25

## Affected vendors

- [Roundcube](https://intel.threadlinqs.com/vendors/roundcube) — 3 CVEs
- [Linux](https://intel.threadlinqs.com/vendors/linux) — 1 CVE
- **OpenStack** — 1 CVE
- [Openclaw](https://intel.threadlinqs.com/vendors/openclaw) — 1 CVE

## Threat activity

10 tracked threats cite CWE-669:

- [Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)](https://intel.threadlinqs.com/threat/TL-2026-2630) — CRITICAL · 2026-09-23
- [CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of Disclosure](https://intel.threadlinqs.com/threat/TL-2026-1831) — HIGH · 2026-08-03
- [ClawHub Marketplace Skills Expose OpenClaw AI Agents to RCE, Data Theft, and Supply-Chain Backdoors (CVE-2026-25253)](https://intel.threadlinqs.com/threat/TL-2026-1212) — HIGH · 2026-07-11
- [Linux Kernel LPE Surge: Copy Fail (CVE-2026-31431), Dirty Frag/Fragnesia (CVE-2026-43284/CVE-2026-43500/CVE-2026-46300), and CrackArmor AppArmor Flaws vs. Defense-in-Depth Mitigations](https://intel.threadlinqs.com/threat/TL-2026-2424) — HIGH · 2026-05-29
- [Roundcube Webmail Pre-Auth SQL Injection in virtuser_query Plugin (CVE-2026-48842) — Patched in 1.6.16 / 1.7.1 Alongside 7 Other Vulnerabilities](https://intel.threadlinqs.com/threat/TL-2026-0616) — HIGH · 2026-05-28
- [CVE-2026-31431 "Copy Fail" — Linux Kernel algif_aead Deterministic Local Privilege Escalation Affecting All Major Distributions](https://intel.threadlinqs.com/threat/TL-2026-0486) — HIGH · 2026-05-08
- [Linux Kernel 'Copy Fail' Local Privilege Escalation (CVE-2026-31431) — algif_aead 4-Byte Page Cache Write to setuid Root](https://intel.threadlinqs.com/threat/TL-2026-0445) — HIGH · 2026-04-30
- [CVE-2026-25253: OpenClaw One-Click RCE via Malicious Link](https://intel.threadlinqs.com/threat/TL-2026-0044) — CRITICAL · 2026-02-03
- [OpenClaw AI Agent Framework Security Concerns Prompt Detection Tooling](https://intel.threadlinqs.com/threat/TL-2026-0056) — MEDIUM · 2026-02-03
- [OpenClaw CVE-2026-25253: One-Click RCE via Token Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-0008) — HIGH · 2026-02-02

## Related weaknesses

- [CWE-664](https://cwe.mitre.org/data/definitions/664.html)

Canonical: https://intel.threadlinqs.com/cwe/CWE-669
Source definition: https://cwe.mitre.org/data/definitions/669.html
Detection rules and IOCs for threats exploiting CWE-669 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
