CWE-706: Use of Incorrectly-Resolved Name or Reference
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.
72 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-78985 — Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveragin
- CVE-2026-87547 — Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveragin
- CVE-2026-87613 — Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potent
- CVE-2026-87618 — Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacke
- CVE-2024-27295 — Directus MySQL accent insensitive email matching
- CVE-2026-25890 — File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL
- CVE-2026-67602 — phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache
- CVE-2026-3125 — SSRF vulnerability in opennextjs-cloudflare via /cdn-cgi/ path normalization bypass
- CVE-2026-35039 — fast-jwt Affected by Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup)
- CVE-2025-58362 — Hono contains a flaw in URL path parsing, potentially leading to path confusion
- CVE-2024-27292 — Docassemble unauthorized access through URL manipulation
- CVE-2025-30357 — NamelessMC Forum Topic Deletion Triggered by Unrelated User Deletion
- CVE-2026-13097 — Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore
- CVE-2026-62190 — OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper
- CVE-2026-29036 — cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding
- CVE-2026-87562 — Incorrect reference resolution in Accessibility in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attac
- CVE-2026-25067 — SmarterTools SmarterMail < Build 9518 Unauthenticated background-of-the-day Path Coercion
- CVE-2026-62685 — File Browser: Colliding username normalization gives two users the same home directory
- CVE-2026-40912 — Traefik: StripPrefixRegex auth bypass via Path/RawPath desync
- CVE-2026-35666 — OpenClaw < 2026.3.22 - Allowlist Bypass via Unregistered Time Dispatch Wrapper
Recently published
- CVE-2026-87618 — Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacke
- CVE-2026-87562 — Incorrect reference resolution in Accessibility in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attac
- CVE-2026-87613 — Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potent
- CVE-2026-87547 — Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveragin
- CVE-2026-79254 — Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote atta
- CVE-2026-79273 — Incorrect reference resolution in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacke
- CVE-2026-79103 — Incorrect reference resolution in Speech in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compr
- CVE-2026-79070 — Incorrect reference resolution in Cache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web
- CVE-2026-79049 — Incorrect reference resolution in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass
- CVE-2026-79264 — Incorrect reference resolution in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass we
- CVE-2026-78942 — Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web
- CVE-2026-78985 — Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveragin
- CVE-2026-67602 — phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache
- CVE-2026-13097 — Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore
- CVE-2026-76039 — Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker
- CVE-2026-29036 — cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding
- CVE-2026-16120 — nextlevelbuilder GoClaw exec_approval.go extractBin name resolution
- CVE-2026-62685 — File Browser: Colliding username normalization gives two users the same home directory
- CVE-2026-62190 — OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper
- CVE-2026-57054 — Junos OS: MX Series: Web filtering doesn't block specifically formatted URLs
More specific weaknesses
- CWE-178 — Improper Handling of Case Sensitivity
- CWE-22 — Path Traversal
- CWE-386 — Symbolic Name not Mapping to Correct Object
- CWE-41 — Improper Resolution of Path Equivalence
- CWE-59 — Link Following
- CWE-66 — Improper Handling of File Names that Identify Virtual Resources
- CWE-827 — Improper Control of Document Type Definition