CWE-15: External Control of System or Configuration Setting
One or more system settings or configuration elements can be externally controlled by a user.
Overview
Allowing external control of system settings can disrupt service or cause an application to behave in unexpected, and potentially malicious ways.
Real-world CVEs
57 recorded CVEs are caused by CWE-15 (External Control of System or Configuration Setting). The highest-severity and most recent are shown first. 14 new CWE-15 CVEs have been recorded so far in 2026 (22 in 2025).