CWE-923— Improper Restriction of Communication Channel to Intended Endpoints
The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.— MITRE CWE catalog
69 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-923page 2 of 2
- CVE-2025-62843MEDIUMCVSS 6.8EG 6.82026-03-20
An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can then exploit the vulnerability to gain the privileges that were intended…
- CVE-2026-12039MEDIUMCVSS 5.7EG 5.72026-06-18
Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network embedded DNS server forwards any queried name to the host resolver whenever the network is internet-connected, without…
- CVE-2026-12539MEDIUMCVSS 5.7EG 5.72026-06-18
Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-apply it to networks rebuilt from disk when the Docker daemon restarts, so a restart-surviving sandbox forwards ICMP to arb…
- CVE-2026-18655MEDIUMCVSS 6.5EG 6.52026-08-03
Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ…
- CVE-2026-22715MEDIUMCVSS 5.9EG 5.92026-02-26
VMWare Workstation and Fusion contain a logic flaw in the management of network packets. Known attack vectors: A malicious actor with administrative privileges on a Guest VM may be able to interrupt or intercept network connections of o…
- CVE-2026-22726MEDIUMCVSS 5.0EG 5.02026-05-01
Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to …
- CVE-2026-23664HIGHCVSS 7.5EG 7.52026-03-10
Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
- CVE-2026-23904HIGHCVSS 7.3EG 7.32026-07-29
Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachab…
- CVE-2026-32303MEDIUMCVSS 5.9EG 5.92026-03-20
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerability allows an attacker to tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub ke…
- CVE-2026-32317MEDIUMCVSS 5.9EG 5.92026-03-20
Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 1.12.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man…
- CVE-2026-32318MEDIUMCVSS 5.9EG 5.92026-03-20
Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.8.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-t…
- CVE-2026-33803MEDIUMCVSS 6.5EG 6.52026-07-09
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact t…
- CVE-2026-34205CRITICALCVSS 9.6EG 9.62026-03-27
Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the internal Docker bridge…
- CVE-2026-55655MEDIUMCVSS 6.1EG 6.12026-06-23
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a …
- CVE-2026-57028HIGHCVSS 7.3EG 7.32026-07-09
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion. Due to an incorrect initialization, …
- CVE-2026-59841HIGHCVSS 7.5EG 7.52026-07-14
A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>
- CVE-2026-62836CRITICALCVSS 10.0EG 10.02026-08-06
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-63226MEDIUMCVSS 5.8EG 5.82026-07-23
Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding…
- CVE-2026-8920HIGHCVSS 8.5EG 8.52026-07-15
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file …
Map vulnerabilities like CWE-923 to your infrastructure
EchelonGraph correlates every CVE — across CWE-923 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →