CWE-341: Predictable from Observable State
A number or object is predictable based on observations that the attacker can make about the state of the system or network, such as time, process ID, etc.
12 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-40780 — Cache poisoning due to weak PRNG
- CVE-2026-42365 — GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability
- CVE-2024-10141 — jsbroks COCO Annotator Session predictable state
- CVE-2026-15571 — Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client
- CVE-2025-42925 — Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)
- CVE-2026-19565 — Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey
Recently published
- CVE-2026-19565 — Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey
- CVE-2026-15571 — Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client
- CVE-2026-42365 — GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability
- CVE-2025-40780 — Cache poisoning due to weak PRNG
- CVE-2025-42925 — Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)
- CVE-2024-10141 — jsbroks COCO Annotator Session predictable state