BaseDraft
CWE-349Acceptance of Extraneous Untrusted Data With Trusted Data
Category: other
Description
The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.
Common consequences· 1
- Access Control / Integrity — Bypass Protection Mechanism, Modify Application DataAn attacker could package untrusted data with trusted data to bypass protection mechanisms to gain access to and possibly modify sensitive data.
Related CAPEC attack patterns· 3
References
Exploits (incoming)3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Cache Poisoningcapec-141 | 100% | live |
| AttackPattern | Manipulating Writeable Configuration Filescapec-75 | 100% | live |
| AttackPattern | DNS Cache Poisoningcapec-142 | 100% | live |
(incoming)4
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-40776cve-2025-40776 | 0% | live |
| Vulnerability | CVE-2025-40778cve-2025-40778 | 0% | live |
| Vulnerability | CVE-2026-32162cve-2026-32162 | 0% | live |
| Vulnerability | CVE-2026-42960cve-2026-42960 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.