CWE-441— Unintended Proxy or Intermediary (Confused Deputy)
The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.— MITRE CWE catalog
193 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-441page 3 of 4
- CVE-2019-3924HIGHCVSS 7.5EG 7.52019-02-20
MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The software will execute user defined network requests to both WAN and LAN clients. A remote unauthenticated attacker can us…
- CVE-2026-72668HIGHCVSS 7.3EG 7.32026-09-26
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the id…
- CVE-2025-48532HIGHCVSS 7.3EG 7.32025-09-04
In markMediaAsFavorite of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed…
- CVE-2025-22441HIGHCVSS 7.3EG 7.32025-09-04
In getContextForResourcesEnsuringCorrectCachedApkPaths of RemoteViews.java, there is a possible way to load arbitrary java code in a privileged context due to a confused deputy. This could lead to local escalation of privilege with no addi…
- CVE-2026-75886HIGHCVSS 7.2EG 7.22026-09-23
A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of the `openshift-session-token` cookie. This allows the…
- CVE-2023-31313HIGHCVSS 7.2EG 7.22026-02-12
An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to send malformed messages to the system management unit (SMU) potentially resulting in arbitrary code execution.
- CVE-2020-26262HIGHCVSS 7.2EG 7.22021-01-13
Coturn is free open source implementation of TURN and STUN Server. Coturn before version 4.5.2 by default does not allow peers to connect and relay packets to loopback addresses in the range of `127.x.x.x`. However, it was observed that wh…
- CVE-2026-106188HIGHCVSS 7.1EG 7.12026-10-06
Confused deputy in SignIn in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-100625HIGHCVSS 7.1EG 7.12026-09-26
Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_backend/public/build/upload.ts) that authorizes a caller against a single build job identified by the supplied builder_job_id and validates only that job's stor…
- CVE-2026-73266HIGHCVSS 7.1EG 7.12026-08-13
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a Manage…
- CVE-2025-48545HIGHCVSS 7.1EG 7.12025-09-04
In isSystemUid of AccountManagerService.java, there is a possible way for an app to access privileged APIs due to a confused deputy. This could lead to local privilege escalation with no additional execution privileges needed. User interac…
- CVE-2026-101907HIGHCVSS 7.0EG 7.02026-09-28
Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter with maxRedirects set to zero and receives …
- CVE-2026-61793MEDIUMCVSS 6.9EG 6.92026-09-17
Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults security.strict = false and security.secret = "" are used, and bas…
- CVE-2026-53931MEDIUMCVSS 6.9EG 6.92026-06-17
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the spreadsheet-import endpoint axiosRequestMake could be used as a generic HTTP proxy. Before the fix it was reachable unauthenticated, and its URL-extension a…
- CVE-2026-55430MEDIUMCVSS 6.8EG 6.82026-07-06
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the workspace app proxy resolves the target app from `httpapi.RequestHost()` which prefers the `X-…
- CVE-2026-39961MEDIUMCVSS 6.8EG 6.82026-04-09
Aiven Operator allows you to provision and manage Aiven Services from your Kubernetes cluster. From 0.31.0 to before 0.37.0, a developer with create permission on ClickhouseUser CRDs in their own namespace can exfiltrate secrets from any o…
- CVE-2026-58739MEDIUMCVSS 6.7EG 6.72026-09-15
In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed …
- CVE-2026-58698MEDIUMCVSS 6.7EG 6.72026-09-15
In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for expl…
- CVE-2026-56992MEDIUMCVSS 6.7EG 6.72026-09-15
In multiple files, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
- CVE-2026-56922MEDIUMCVSS 6.7EG 6.72026-09-15
In CPM, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
- CVE-2026-56879MEDIUMCVSS 6.7EG 6.72026-09-15
In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corruption due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
- CVE-2018-12182MEDIUMCVSS 6.7EG 6.72019-03-27
Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
- CVE-2025-48598MEDIUMCVSS 6.6EG 6.62025-12-08
In multiple locations, there is a possible way to alter the primary user's face unlock settings due to a confused deputy. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction …
- CVE-2026-107336MEDIUMCVSS 6.5EG 6.52026-10-08
Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a case-insensitive regex matcher but a case-sensitive rewrite. A request whose path segment is not exact-lowercase (for example /IDDASH2ARK/...) …
- CVE-2026-106266MEDIUMCVSS 6.5EG 6.52026-10-06
Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security s…
- CVE-2026-106286MEDIUMCVSS 6.5EG 6.52026-10-06
Confused deputy in Omnibox in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)
- CVE-2026-95328MEDIUMCVSS 6.5EG 6.52026-09-29
Confused deputy in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Low)
- CVE-2026-73424MEDIUMCVSS 6.5EG 6.52026-08-17
Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/integrations/vercel/src/serverless/entrypoint.ts accepts x_astro_path for the public /_isr function based only on the x-ve…
- CVE-2026-72640MEDIUMCVSS 6.5EG 6.52026-08-13
The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets it manages, and it accepts the namespace recorded in each reference without validating that the reference is authorized for the …
- CVE-2026-16456MEDIUMCVSS 6.5EG 6.52026-08-10
A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the `loadSecret` function. This function improperly reads the Secret namespace from user-contr…
- CVE-2026-44964MEDIUMCVSS 6.5EG 6.52026-08-07
In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with no permission guard. A co-installed application can launch it with attacker-controlled Intent extras, including a full…
- CVE-2026-13062MEDIUMCVSS 6.5EG 6.52026-07-22
An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mon…
- CVE-2026-49086MEDIUMCVSS 6.5EG 6.52026-07-06
Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR component. The camel-dapr Dapr Pub/Sub consumer (DaprPubSubConsumer) copied two fields from each inbound CloudEvent - its P…
- CVE-2026-27624MEDIUMCVSS 6.5EG 6.52026-02-25
Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using "denied-peer-ip" and/or default loopback restrictions. CVE-2020-26262 addressed bypasses involvi…
- CVE-2024-0387MEDIUMCVSS 6.5EG 6.52024-02-26
The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access con…
- CVE-2020-5412MEDIUMCVSS 6.5EG 6.52020-08-07
Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server…
- CVE-2019-3996MEDIUMCVSS 6.5EG 6.52019-12-17
ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST requests.
- CVE-2026-106462MEDIUMCVSS 6.4EG 6.42026-10-06
Backstage is an open framework for building developer portals. Prior to 1.54.6, scaffolder source-control actions may not consistently enforce intended credential boundaries. An authenticated user could cause an affected action to fall bac…
- CVE-2024-34068MEDIUMCVSS 6.4EG 6.42024-05-03
Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able to bypass the previously implemented access control (GHSA-6rg3-8h8x-5xfv) that prevents accessing internal e…
- CVE-2026-81303MEDIUMCVSS 6.3EG 6.32026-09-15
A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without validati…
- CVE-2026-63643MEDIUMCVSS 6.3EG 6.32026-08-18
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/calendar/node_helper.js accepts an attacker-controlled URL, authentication data, and selfSignedCert setting through …
- CVE-2023-33188MEDIUMCVSS 6.3EG 6.32023-05-27
Omni-notes is an open source note-taking application for Android. The Omni-notes Android app had an insufficient path validation vulnerability when displaying the details of a note received through an externally-provided intent. The paths …
- CVE-2026-54663MEDIUMCVSS 6.1EG 6.12026-07-29
swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts warmUpRemoteSchemasCache resolves external $ref URLs and fetchRemoteSchemaDocument uses isHttpUrl…
- CVE-2026-50169MEDIUMCVSS 6.1EG 6.12026-06-15
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15 20.3.22, and 19.2.23, an issue in the @angular/service-worker package comprom…
- CVE-2026-27124MEDIUMCVSS 6.1EG 6.12026-04-03
FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the GitHubProvider OAuth integration, which allows authentication to a FastMCP MCP server via a FastMCP OAuthProxy using GitHub OAuth, i…
- CVE-2021-32773MEDIUMCVSS 6.1EG 6.12021-07-20
Racket is a general-purpose programming language and an ecosystem for language-oriented programming. In versions prior to 8.2, code evaluated using the Racket sandbox could cause system modules to incorrectly use attacker-created modules i…
- CVE-2026-93320MEDIUMCVSS 6.0EG 6.02026-10-05
BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.
- CVE-2026-12879MEDIUMCVSS 5.9EG 5.92026-07-09
An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data. This vulnerability was patched on 1…
- CVE-2018-16598MEDIUMCVSS 5.9EG 5.92018-12-06
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. In xProcessReceivedUDPPacket and prvParseDNSReply, any recei…
- CVE-2026-50022MEDIUMCVSS 5.8EG 5.82026-09-17
Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSolrIndex.query forwards the client-controlled qt parameter through Apache SolrJ from search endpoints such as /d1/mn/v2/…
Map vulnerabilities like CWE-441 to your infrastructure
EchelonGraph correlates every CVE — across CWE-441 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →