CWE-923: Improper Restriction of Communication Channel to Intended Endpoints
The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.
64 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-34205 — Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Mode
- CVE-2025-61939 — Columbia Weather Systems MicroServer Improper Restriction of Communication Channel to Intended Endpoints
- CVE-2025-20261 — Cisco Integrated Management Controller Privilege Escalation Vulnerability
- CVE-2025-58742 — Insufficient Configuration Protections Enable Database Credential Interception in Milner ImageDirector Capture
- CVE-2024-26131 — Element Android Intent Redirection
- CVE-2025-29986 — Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intend
- CVE-2025-12357 — International Standards Organization ISO 15118-2 Improper Restriction of Communication Channel to Intended Endpoints
- CVE-2024-47490 — Junos OS Evolved: ACX 7000 Series: Receipt of specific transit MPLS packets causes resources to be exhausted
- CVE-2024-47125 — Improper Restriction of Communication Channel to Intended Endpoints in goTenna Pro
- CVE-2026-32303 — Cryptomator: Tampered vault configuration allows MITM attack on Hub API
- CVE-2025-23178 — Ribbon Communications - CWE-923: Improper Restriction of Communication Channel to Intended Endpoints
- CVE-2025-35978 — Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and Updat
- CVE-2024-26013 — A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS versio
- CVE-2026-8920 — Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wa
- CVE-2025-31144 — Quick Agent V3 and Quick Agent V2 contain an issue with improper restriction of communication channel to intended endpoi
- CVE-2024-39537 — Junos OS Evolved: ACX7000 Series: Ports which have been inadvertently exposed can be reached over the network
- CVE-2025-48999 — Dataease Redshift Data Source JDBC Connection Parameters Not Verified Leads to RCE Vulnerability
- CVE-2025-46566 — Dataease redshift JDBC Connection Remote Code Execution
- CVE-2026-32318 — Cryptomator for IOS: Tampered vault configuration allows MITM attack on Hub API
- CVE-2026-32317 — Cryptomator for Android: Tampered vault configuration allows MITM attack on Hub API
Recently published
- CVE-2026-87734 — An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial
- CVE-2026-18655 — Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
- CVE-2026-23904 — Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy
- CVE-2026-63226 — Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port for
- CVE-2026-8920 — Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wa
- CVE-2026-59841 — A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.
- CVE-2026-57028 — Junos OS Evolved: A port which has been inadvertently exposed can be reached by an attacker
- CVE-2026-33803 — Junos OS Evolved: A port which has been inadvertently exposed can be reached by an attacker
- CVE-2026-55655 — Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions
- CVE-2026-12539 — Docker Sandboxes ICMP egress restriction bypass after daemon restart
- CVE-2026-12039 — Docker Sandboxes network egress allowlist bypass via unfiltered DNS resolution
- CVE-2025-36145 — Multiple Vulnerabilities in watsonx.data
- CVE-2026-22726 — Route Services Firewall Bypass
- CVE-2025-36180 — Inadequate Pod Communication Restrictions, affects watsonx.data
- CVE-2026-34205 — Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Mode
- CVE-2025-36438 — Multiple Vulnerabilities in IBM Concert Software
- CVE-2026-32317 — Cryptomator for Android: Tampered vault configuration allows MITM attack on Hub API
- CVE-2026-32318 — Cryptomator for IOS: Tampered vault configuration allows MITM attack on Hub API
- CVE-2026-32303 — Cryptomator: Tampered vault configuration allows MITM attack on Hub API
- CVE-2025-62843 — QuRouter
More specific weaknesses
- CWE-1275 — Sensitive Cookie with Improper SameSite Attribute
- CWE-297 — Improper Validation of Certificate with Host Mismatch
- CWE-300 — Channel Accessible by Non-Endpoint
- CWE-419 — Unprotected Primary Channel
- CWE-420 — Unprotected Alternate Channel
- CWE-940 — Improper Verification of Source of a Communication Channel
- CWE-941 — Incorrectly Specified Destination in a Communication Channel