CWE-638: Not Using Complete Mediation

moderate-risk

The product does not perform access checks on a resource every time the resource is accessed by an entity, which can create resultant weaknesses if that entity's rights or privileges change over time.

Abstraction: Class

Common Consequences

Integrity Gain Privileges or Assume Identity

Real-World Examples (1)

CVE CVSS EPSS KEV
CVE-2024-56512 5.4 29.2%
41
/ 100
moderate-risk
Active Threat 41/50 · Critical
Exploit Availability 0/50 · Minimal