CWE-283: Unverified Ownership
The product does not properly verify that a critical resource is owned by the proper entity.
Last updated
Overview
CWE-283 (Unverified Ownership) is a base-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
17 recorded CVEs are caused by CWE-283 (Unverified Ownership). The highest-severity and most recent are shown first. 6 new CWE-283 CVEs have been recorded so far in 2026 (5 in 2025).
- CVE-2026-26016
Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization
Critical · CVSS 9.2 · EPSS 23th2026-02-19 - CVE-2026-29788
TSPortal: Anyone can forge self-deletion requests of any user
High · CVSS 8.4 · EPSS 17th2026-03-06 - CVE-2025-43882High · CVSS 7.8 · EPSS 2th2025-08-27