CWE-708: Incorrect Ownership Assignment
The product assigns an owner to a resource, but the owner is outside of the intended control sphere.
21 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-52561 — A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (b
- CVE-2026-40196 — HomeBox has Unauthorized API Access via Retained defaultGroup ID After Group Access Revocation
- CVE-2024-41773 — IBM Global Configuration Management incorrect ownership assignment
- CVE-2026-32691 — Timing ownership claim attack on new external back-end secrets
- CVE-2025-14262 — Jobs can be saved as workflows with wrong permissions on KNIME Business Hub
- CVE-2025-5069 — Incorrect Ownership Assignment in GitLab
- CVE-2026-6469 — PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership
- CVE-2024-9633 — Incorrect Ownership Assignment in GitLab
- CVE-2025-5467 — Ubuntu Apport Insecure File Permissions Vulnerability
Recently published
- CVE-2026-6469 — PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership
- CVE-2026-40196 — HomeBox has Unauthorized API Access via Retained defaultGroup ID After Group Access Revocation
- CVE-2026-32691 — Timing ownership claim attack on new external back-end secrets
- CVE-2025-5467 — Ubuntu Apport Insecure File Permissions Vulnerability
- CVE-2025-14262 — Jobs can be saved as workflows with wrong permissions on KNIME Business Hub
- CVE-2025-5069 — Incorrect Ownership Assignment in GitLab
- CVE-2024-52561 — A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (b
- CVE-2024-9633 — Incorrect Ownership Assignment in GitLab
- CVE-2024-41773 — IBM Global Configuration Management incorrect ownership assignment