BaseIncomplete
CWE-359Exposure of Private Personal Information to an Unauthorized Actor
Category: auth
Description
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
Common consequences· 1
- Confidentiality — Read Application Data
Potential mitigations· 3
- [Requirements]
- [Architecture and Design]
- [Implementation, Operation]
Related CAPEC attack patterns· 4
References
Exploits (incoming)4
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Cross Site Identificationcapec-467 | 100% | live |
| AttackPattern | Probe iOS Screenshotscapec-498 | 100% | live |
| AttackPattern | Shoulder Surfingcapec-508 | 100% | live |
| AttackPattern | Evercookiecapec-464 | 100% | live |
Compliance frameworks addressing this (incoming)3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| ComplianceControl | iso27701-a.7.4.1 | 100% | live |
| ComplianceControl | iso27701-a.7.4.5 | 100% | live |
| ComplianceControl | owasp_llm_top10-llm02 | 100% | live |
(incoming)2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-11959cve-2025-11959 | 0% | live |
| Vulnerability | CVE-2025-66172cve-2025-66172 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.