Cyber Posture

CWE · MITRE source

CWE-346Origin Validation Error

Abstraction: Class · CVEs in our corpus: 482

The product does not properly verify that the source of data or communication is valid.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (5)AI

Showing the 4 most specific. Generic controls that address many weakness types are collapsed below.

Control Title Family Why it addresses this CWE
SC-11Trusted PathSCTrusted path establishment enforces validation that the communication originates from and reaches only the intended trusted system components.
SC-20Secure Name/Address Resolution Service (Authoritative Source)SCEnforces validation of the true origin of DNS responses via signatures and chain-of-trust mechanisms.
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)SCEnforces origin validation of name/address data, eliminating reliance on unverified or impersonated DNS sources.
IA-9Service Identification and AuthenticationIARequires unique identification of the service before communications, addressing failures to validate the origin of the interaction.
Show 1 more broadly-applicable controls
SC-23Session AuthenticitySCMandates origin validation so that only legitimate endpoints can continue the authenticated session.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2015-4495 KEV8.18.80.71572015-08-08
CVE-2020-169526.28.60.75082020-10-16
CVE-2009-11855.40.00.89512009-04-17
CVE-2022-419245.19.60.53562022-11-23
CVE-2019-39804.99.80.49232019-10-08
CVE-2021-262914.69.10.46102021-04-23
CVE-2024-238984.08.80.36872024-01-24
CVE-2021-211352.86.50.24932021-02-09
CVE-2021-211362.86.50.25152021-02-09
CVE-2020-14082.78.80.15872020-07-14
CVE-2025-342912.68.80.13272025-12-05
CVE-2018-157232.49.80.07322018-12-20
CVE-2020-14492.47.80.14772020-07-14
CVE-2019-80692.29.80.03432019-09-12
CVE-2000-12182.19.80.02222000-04-14
CVE-2016-51682.17.50.09632017-04-21
CVE-2019-150202.19.80.01582019-10-09
CVE-2003-01742.09.80.00362003-05-12
CVE-2017-132742.09.80.00062018-04-04
CVE-2018-51162.09.80.00462018-06-11
CVE-2018-54092.09.80.00192019-05-08
CVE-2019-165172.09.80.00222020-01-23
CVE-2019-46402.09.80.00122020-02-19
CVE-2020-265272.09.80.00442020-10-02
CVE-2021-377052.010.00.00472021-08-13