The product does not properly verify that a critical resource is owned by the proper entity.
Volume of CVEs assigned to CWE-283 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-20912CRITICAL Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release | Jan 22, 2026 | 9.1 | 35 | NO | NO |
CVE-2024-27903CRITICAL OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact w | Jul 8, 2024 | 9.8 | 33 | NO | NO |
CVE-2026-4269HIGH A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to cod | Mar 16, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-26016HIGH Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in multiple controllers | Feb 19, 2026 | 8.1 | 27 | NO | NO |
CVE-2025-43882HIGH Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A local low-privileged attacker could potentially exploit this vulnerability leading | Aug 27, 2025 | 7.8 | 25 | NO | NO |
CVE-2021-24501HIGH The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifyin | Aug 9, 2021 | 8.1 | 25 | NO | NO |
CVE-2021-24500HIGH Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. | Aug 9, 2021 | 8.1 | 25 | NO | NO |
CVE-2026-44707MEDIUM Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email confi | May 26, 2026 | 6.8 | 24 | NO | NO |
CVE-2026-44562MEDIUM Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/models/import endpoint allows users with the wor | May 15, 2026 | 6.5 | 24 | NO | NO |
CVE-2020-8554MEDIUM Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Addit | Jan 21, 2021 | 5.0 | 24 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.