CWE-15: External Control of System or Configuration Setting
One or more system settings or configuration elements can be externally controlled by a user.
Last updated
Overview
Allowing external control of system settings can disrupt service or cause an application to behave in unexpected, and potentially malicious ways.
Real-world CVEs
59 recorded CVEs are caused by CWE-15 (External Control of System or Configuration Setting). The highest-severity and most recent are shown first. 16 new CWE-15 CVEs have been recorded so far in 2026 (22 in 2025).