CWE-412: Unrestricted Externally Accessible Lock
The product properly checks for the existence of a lock, but the lock can be externally controlled or influenced by an actor that is outside of the intended sphere of control.
6 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-25612 — Internal ResourceId collision may affect unrelated collections
- CVE-2026-82312 — OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial
Recently published
- CVE-2026-82312 — OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial
- CVE-2026-25612 — Internal ResourceId collision may affect unrelated collections