CWE-441— Unintended Proxy or Intermediary (Confused Deputy)
The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.— MITRE CWE catalog
193 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-441page 2 of 4
- CVE-2026-106221HIGHCVSS 8.3EG 8.32026-10-06
Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-106228HIGHCVSS 8.3EG 8.32026-10-06
Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security…
- CVE-2026-87582HIGHCVSS 8.3EG 8.32026-09-09
Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium securit…
- CVE-2026-56675HIGHCVSS 8.3EG 8.32026-07-10
9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a same-host reverse proxy that forwards public traffic to the backend through 127.0.0.1 cause…
- CVE-2026-42313HIGHCVSS 8.3EG 8.32026-05-11
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand…
- CVE-2026-86600HIGHCVSS 8.2EG 8.22026-09-08
In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify th…
- CVE-2026-77348HIGHCVSS 8.2EG 8.22026-08-31
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php by disabling cU…
- CVE-2026-43910HIGHCVSS 8.2EG 8.22026-07-28
Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when directConnect(true) is enabled, AppiumCommandExecutor.setDirectConnect() reads the directCon…
- CVE-2025-23217HIGHCVSS 8.2EG 8.22025-02-06
mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmweb is a web-based interface for mitmproxy. In mitmweb 11.1.1 and below, a malicious client can use mitmweb's proxy serv…
- CVE-2026-106301HIGHCVSS 8.1EG 8.12026-10-06
Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium s…
- CVE-2026-24470HIGHCVSS 8.1EG 8.12026-01-26
Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permissions to create an Ingress and a Service of type ExternalName can create routes t…
- CVE-2019-1841HIGHCVSS 6.5EG 8.12019-04-18
A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attacker to access to internal services without additional authentication. The vulnerability is due to insufficient validatio…
- CVE-2026-55225HIGHCVSS 8.0EG 8.02026-06-18
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator watch…
- CVE-2026-28648HIGHCVSS 7.8EG 7.82026-10-05
In Settings, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2026-55270HIGHCVSS 7.8EG 7.82026-10-05
In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl…
- CVE-2026-56945HIGHCVSS 7.8EG 7.82026-09-15
In VPU, there is a possible out-of-bounds write due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2026-45520HIGHCVSS 7.8EG 7.82026-09-08
In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…
- CVE-2026-28657HIGHCVSS 7.8EG 7.82026-09-08
In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible unauthorized URI permission grant due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User…
- CVE-2026-28644HIGHCVSS 7.8EG 7.82026-09-08
In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interact…
- CVE-2026-28636HIGHCVSS 7.8EG 7.82026-09-08
In setupLayout of PickActivity.java, there is a possible bypass of the "Install unknown apps" security restriction due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. U…
- CVE-2026-28624HIGHCVSS 7.8EG 7.82026-09-08
In multiple locations, there is a possible read/write access to files without the proper permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…
- CVE-2026-28616HIGHCVSS 7.8EG 7.82026-09-08
In Setup Wizard, there is a possible way to force connection to a malicious network due to confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- CVE-2026-28614HIGHCVSS 7.8EG 7.82026-09-08
In onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo…
- CVE-2026-28607HIGHCVSS 7.8EG 7.82026-09-08
In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction …
- CVE-2026-28603HIGHCVSS 7.8EG 7.82026-09-08
In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible read/write access to private files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges n…
- CVE-2026-28600HIGHCVSS 7.8EG 7.82026-09-08
In onCreate of PaymentDefaultDialog.java, there is a possible way to change default payment app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is …
- CVE-2026-0098HIGHCVSS 7.8EG 7.82026-06-01
In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interact…
- CVE-2025-48570HIGHCVSS 7.8EG 7.82026-06-01
In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2025-48646HIGHCVSS 7.8EG 7.82026-03-02
In executeRequest of ActivityStarter.java, there is a possible launch anywhere due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploi…
- CVE-2025-48628HIGHCVSS 7.8EG 7.82025-12-08
In validateIconUserBoundary of PrintManagerService.java, there is a possible cross-user image leak due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction …
- CVE-2025-48586HIGHCVSS 7.8EG 7.82025-12-08
In onActivityResult of EditFdnContactScreen.java, there is a possible way to leak contacts from the work profile due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. Use…
- CVE-2025-48555HIGHCVSS 7.8EG 7.82025-12-08
In multiple functions of NotificationStation.java, there is a possible cross-profile information disclosure due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User int…
- CVE-2025-48536HIGHCVSS 7.8EG 7.82025-12-08
In grantAllowlistedPackagePermissions of SettingsSliceProvider.java, there is a possible way for a third party app to modify secure settings due to a confused deputy. This could lead to local escalation of privilege with no additional exec…
- CVE-2025-22420HIGHCVSS 7.8EG 7.82025-12-08
In multiple locations, there is a possible way to leak audio files across user profiles due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need…
- CVE-2025-32320HIGHCVSS 7.8EG 7.82025-09-05
In System UI, there is a possible way to view other users' images due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2025-32346HIGHCVSS 7.8EG 7.82025-09-04
In onActivityResult of VoicemailSettingsActivity.java, there is a possible work profile contact number leak due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User int…
- CVE-2025-32326HIGHCVSS 7.8EG 7.82025-09-04
In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent security check due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User…
- CVE-2025-32324HIGHCVSS 7.8EG 7.82025-09-04
In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is …
- CVE-2025-32321HIGHCVSS 7.8EG 7.82025-09-04
In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent type check due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User int…
- CVE-2025-26454HIGHCVSS 7.8EG 7.82025-09-04
In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access data from another user due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges n…
- CVE-2025-26452HIGHCVSS 7.8EG 7.82025-09-04
In loadDrawableForCookie of ResourcesImpl.java, there is a possible way to access task snapshots of other apps due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User …
- CVE-2025-22418HIGHCVSS 7.8EG 7.82025-09-02
In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2025-22416HIGHCVSS 7.8EG 7.82025-09-02
In onCreate of ChooserActivity.java , there is a possible way to view other users' images due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne…
- CVE-2026-57042HIGHCVSS 6.7EG 7.82026-09-15
In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for e…
- CVE-2026-53514HIGHCVSS 7.7EG 7.72026-07-07
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside the invited mailbox and requireEmailVerificationOnInvitation: true is not enabl…
- CVE-2026-49821HIGHCVSS 7.7EG 7.72026-06-10
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's buildermgr controller processed Package CRDs without verifying…
- CVE-2026-101905HIGHCVSS 7.6EG 7.62026-09-28
Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process prototype-pol…
- CVE-2026-107232HIGHCVSS 7.5EG 7.52026-10-07
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 on 3.x and 2.16.1 on 2.x, the client infers that an HTTP proxy tunnel exists from the las…
- CVE-2026-86003HIGHCVSS 7.5EG 7.52026-09-16
CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.Msg…
- CVE-2026-46592HIGHCVSS 7.5EG 7.52026-07-06
Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP component. The camel-cxf producer selects which SOAP operation to invoke on the backend service from the operationName …
Map vulnerabilities like CWE-441 to your infrastructure
EchelonGraph correlates every CVE — across CWE-441 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →