ClassDraft
CWE-668Exposure of Resource to Wrong Sphere
Category: data-exposure
Description
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Common consequences· 3
- Confidentiality — Read Application DataAn adversary that gains access to a resource exposed to a wrong sphere could potentially retrieve private data from that resource, thus breaking the intended confidentiality of that data.
- Integrity — Modify Application DataAn adversary that gains access to a resource exposed to a wrong sphere could potentially modify data held within that resource, thus breaking the intended integrity of that data and causing the system relying on that resource to make unintended decisions.
- Other — Varies by ContextThe consequences may vary widely depending on how the product uses the affected resource.
References
Compliance frameworks addressing this (incoming)23
| Type | Target | Confidence | Tier |
|---|---|---|---|
| ComplianceControl | nist_csf-de | 100% | live |
| ComplianceControl | pci_dss_v4-r2 | 100% | live |
| ComplianceControl | dora-art17 | 100% | live |
| ComplianceControl | pci_dss_v4-r12 | 100% | live |
| ComplianceControl | cis_v8-4 | 100% | live |
| ComplianceControl | nist_csf-gv | 100% | live |
| ComplianceControl | dora-art25 | 100% | live |
| ComplianceControl | owasp_llm_top10-llm06 | 100% | live |
| ComplianceControl | iso27001-a.5.23 | 100% | live |
| ComplianceControl | cis_v8-13 | 100% | live |
| ComplianceControl | nis2-art21f | 100% | live |
| ComplianceControl | owasp_api_top10-api09 | 100% | live |
| ComplianceControl | iso27001-a.8.21 | 100% | live |
| ComplianceControl | iso27701-a.7.2.1 | 100% | live |
| ComplianceControl | dora-art28 | 100% | live |
| ComplianceControl | owasp_llm_top10-llm02 | 100% | live |
| ComplianceControl | nis2-art21a | 100% | live |
| ComplianceControl | nist_csf-id | 100% | live |
| ComplianceControl | gdpr-art35 | 100% | live |
| ComplianceControl | iso27001-a.8.9 | 100% | live |
| ComplianceControl | iso27701-a.7.4.1 | 100% | live |
| ComplianceControl | iso27701-a.7.4.5 | 95% | live |
| ComplianceControl | iso27701-a.7.3.1 | 95% | live |
(incoming)19
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-15114cve-2025-15114 | 0% | live |
| Vulnerability | CVE-2025-25176cve-2025-25176 | 0% | live |
| Vulnerability | CVE-2025-2857cve-2025-2857 | 0% | live |
| Vulnerability | CVE-2025-55583cve-2025-55583 | 0% | live |
| Vulnerability | CVE-2026-20160cve-2026-20160 | 0% | live |
| Vulnerability | CVE-2026-25643cve-2026-25643 | 0% | live |
| Vulnerability | CVE-2026-25725cve-2026-25725 | 0% | live |
| Vulnerability | CVE-2026-26057cve-2026-26057 | 0% | live |
| Vulnerability | CVE-2026-27466cve-2026-27466 | 0% | live |
| Vulnerability | CVE-2026-29093cve-2026-29093 | 0% | live |
| Vulnerability | CVE-2026-33573cve-2026-33573 | 0% | live |
| Vulnerability | CVE-2026-34765cve-2026-34765 | 0% | live |
| Vulnerability | CVE-2026-39911cve-2026-39911 | 0% | live |
| Vulnerability | CVE-2026-44008cve-2026-44008 | 0% | live |
| Vulnerability | CVE-2026-44009cve-2026-44009 | 0% | live |
| Vulnerability | CVE-2026-44552cve-2026-44552 | 0% | live |
| Vulnerability | CVE-2026-45411cve-2026-45411 | 0% | live |
| Vulnerability | CVE-2026-8958cve-2026-8958 | 0% | live |
| KEVEntry | Microsoft Word Information Disclosure Vulnerabilitykev-cve-2023-36761 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.