The product assigns an owner to a resource, but the owner is outside of the intended control sphere.
Volume of CVEs assigned to CWE-708 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32726CRITICAL Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. | Jul 12, 2021 | 9.8 | 30 | NO | NO |
CVE-2026-40196HIGH HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being | Apr 17, 2026 | 8.1 | 26 | NO | NO |
CVE-2023-4008CRITICAL An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 | Aug 3, 2023 | 9.8 | 24 | NO | NO |
CVE-2023-20044HIGH A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges.
This vulnerability is due to insecure file permissions. An a | Jan 20, 2023 | 7.3 | 24 | NO | NO |
CVE-2022-33737HIGH The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password | Jul 6, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-22189HIGH An Incorrect Ownership Assignment vulnerability in Juniper Networks Contrail Service Orchestration (CSO) allows a locally authenticated user to have their permissions elevated with | Apr 14, 2022 | 7.8 | 24 | NO | NO |
CVE-2024-52561HIGH A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is deleted | Jun 3, 2025 | 7.8 | 23 | NO | NO |
CVE-2025-5069MEDIUM An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated us | Sep 26, 2025 | 6.5 | 22 | NO | NO |
CVE-2023-20043MEDIUM A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges.
This vulnerability is due to insecure file permissions. An a | Jan 20, 2023 | 6.7 | 22 | NO | NO |
CVE-2021-32689MEDIUM Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2, if a user was able to reuse an earlier used username, they could get | Jul 12, 2021 | 6.5 | 22 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.