CWE-346: Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
Overview
CWE-346 (Origin Validation Error) is a class-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
290 recorded CVEs are caused by CWE-346 (Origin Validation Error), including 2 in CISA's KEV (Known Exploited Vulnerabilities) catalog. KEVs are shown first. 83 new CWE-346 CVEs have been recorded so far in 2026 (68 in 2025).