CWE-441: Confused Deputy
The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.
90 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-83548 — A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern
- CVE-2025-68667 — Conduit-derived homeservers are affected by a Confused Deputy and Improper Input Validation issue
- CVE-2026-87582 — Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised th
- CVE-2025-64125 — Nuvation Energy nCloud Client-to-Client Communication
- CVE-2026-24471 — Improper Validation in Conduit-derived homeservers resulting in Unintended Proxy or Intermediary ('Confused Deputy')
- CVE-2025-25306 — Misskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated Notes
- CVE-2025-23217 — Mitmweb API Authentication Bypass Using Proxy Server
- CVE-2026-42933 — Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs
- CVE-2025-47269 — code-server session cookie can be extracted by having user visit specially crafted proxy URL
- CVE-2026-72526 — Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation
- CVE-2026-67567 — Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction
- CVE-2026-27124 — FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities
- CVE-2026-24470 — Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName
- CVE-2026-70398 — Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace
- CVE-2026-53513 — Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration
- CVE-2025-64123 — Nuvation Energy Multi-Stack Controller Proxy service allows arbitrary BMS access
- CVE-2026-23751 — Kofax Capture 6.0.0.0 Unauthenticated File Read/Write & SMB Coercion via .NET Remoting
- CVE-2026-15183 — Input Validation Vulnerabilities in Snowflake Spark Connector
- CVE-2026-7381 — Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting
- CVE-2026-44945 — Cross-Cluster Impersonation Confused-Deputy Privilege Escalation
Recently published
- CVE-2026-87502 — Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the
- CVE-2026-87582 — Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised th
- CVE-2026-87442 — Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the r
- CVE-2026-87453 — Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised
- CVE-2026-86600 — Workload identity attestation generated before login host validation in Snowflake drivers
- CVE-2026-86115 — Sim before 0.8.14 Confused Deputy in Tool URL Routing Mints an Internal Token for a User-Supplied /api/ Path
- CVE-2026-84329 — Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker wh
- CVE-2026-83548 — A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern
- CVE-2026-77348 — Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php`
- CVE-2026-67567 — Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction
- CVE-2026-63643 — MagicMirror: ssrf calendar .js
- CVE-2026-73424 — Astro: Unauthenticated path override in the @astrojs/vercel ISR function
- CVE-2026-72640 — Unintended Proxy or Intermediary in Elastic Cloud on Kubernetes Leading to Cross-Namespace Secret Disclosure
- CVE-2026-73266 — Clusterclaims-controller: confused deputy: tenant-controlled clusterclaim labels propagated to managedcluster, enabling cross-tenant managedclusterset join
- CVE-2026-70398 — Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace
- CVE-2026-72526 — Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation
- CVE-2026-73079 — Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstream endpoints using pooled account credentials
- CVE-2026-16456 — Odh-model-controller: odh-model-controller: cross-namespace secret read via nim account crd confused deputy
- CVE-2026-44964 — The OnCallNotificationActivity in the Datadog Android application is declared android:exported="true" in AndroidManifest
- CVE-2026-44945 — Cross-Cluster Impersonation Confused-Deputy Privilege Escalation