The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.
Volume of CVEs assigned to CWE-923 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
65 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-8920HIGH Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operation | Jul 15, 2026 | 8.5 | 37 | NO | NO |
CVE-2026-59841HIGH A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privil | Jul 14, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-34205CRITICAL Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose un | Mar 27, 2026 | 9.6 | 33 | NO | NO |
CVE-2026-55655MEDIUM A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred a | Jun 23, 2026 | 6.1 | 30 | NO | NO |
CVE-2026-57028HIGH An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause | Jul 9, 2026 | 7.3 | 29 | NO | NO |
CVE-2026-33803MEDIUM An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause | Jul 9, 2026 | 6.5 | 29 | NO | NO |
CVE-2025-36180HIGH IBM watsonx.data 2.2 through 2.3 IBM Lakehouse does not properly restrict communication between pods which could allow an attacker to transfer data between pods without restriction | Apr 30, 2026 | 7.5 | 29 | NO | NO |
CVE-2024-41889CRITICAL Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attac | Aug 5, 2024 | 9.8 | 29 | NO | NO |
CVE-2021-38487CRITICAL RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted packet to flood target devices wi | May 5, 2022 | 9.1 | 29 | NO | NO |
CVE-2019-17440CRITICAL Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation Switch Management Card (SMC) may allow an attacker with network | Dec 20, 2019 | 9.8 | 29 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.