The System-On-A-Chip (SoC) implements a Security Token mechanism to differentiate what actions are allowed or disallowed when a transaction originates from an entity. However, the Security Tokens are improperly protected.
Volume of CVEs assigned to CWE-1259 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25700HIGH Improper Restriction of Security Token Assignment vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
Previously issued administrative tokens were no | Jun 10, 2026 | 7.2 | 28 | NO | NO |
CVE-2024-29371HIGH In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression rat | Dec 17, 2025 | 7.5 | 27 | NO | NO |
CVE-2024-36533CRITICAL Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | Jul 24, 2024 | 9.8 | 26 | NO | NO |
CVE-2025-51306MEDIUM In Gatling Enterprise versions below 1.25.0, a user logging-out can still use his session token to continue using the application without expiration, due to incorrect session manag | Aug 6, 2025 | 6.5 | 23 | NO | NO |
CVE-2025-56207MEDIUM A security flaw in the '_transfer' function of a smart contract implementation for Money Making Opportunity (MMO), an Ethereum ERC721 Non-Fungible Token (NFT) project, allows users | Sep 30, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-4598MEDIUM An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended b | Sep 23, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-36111MEDIUM KubePi is a K8s panel. Starting in version 1.6.3 and prior to version 1.8.0, there is a defect in the KubePi JWT token verification. The JWT key in the default configuration file i | Jul 25, 2024 | 6.3 | 22 | NO | NO |
CVE-2022-23541MEDIUM jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured so that passing a poorly implemented key retrieval function | Dec 22, 2022 | 6.3 | 22 | NO | NO |
CVE-2025-50579MEDIUM A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to improper validation of the Origin heade | Aug 19, 2025 | 5.3 | 20 | NO | NO |
CVE-2022-23551MEDIUM aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI component in AAD Pod Identity inter | Dec 21, 2022 | 5.3 | 20 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.