BaseIncomplete
CWE-708Incorrect Ownership Assignment
Category: other
Description
The product assigns an owner to a resource, but the owner is outside of the intended control sphere.
This may allow the resource to be manipulated by actors outside of the intended control sphere.
Common consequences· 1
- Confidentiality / Integrity — Read Application Data, Modify Application DataAn attacker could read and modify data for which they do not have permissions to access directly.
Potential mitigations· 1
- [Policy]Periodically review the privileges and their owners.
References
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2026-40196cve-2026-40196 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.