The product calls a function, procedure, or routine, but the caller specifies an argument that is the wrong data type, which may lead to resultant weaknesses.
Last updated
This weakness is most likely to occur in loosely typed languages, or in strongly typed languages in which the types of variable arguments cannot be enforced at compilation time, or where there is implicit casting.
5 recorded CVEs are caused by CWE-686 (Function Call With Incorrect Argument Type). The highest-severity and most recent are shown first. 2 new CWE-686 CVEs have been recorded so far in 2026 (1 in 2025).
JIT miscompilation in the JavaScript Engine: JIT component
JIT miscompilation in the JavaScript Engine: JIT component
Junos OS Evolved: PTX Series: If SRTE tunnels provisioned via PCEP are present and specific gRPC queries are received evo-aftmand crashes
Postgresql: memory disclosure in aggregate function calls
What can happen when CWE-686 is exploited.
Quality Degradation
Affects: Other
Typically introduced during these phases of the software lifecycle.
Because this function call often produces incorrect behavior, it will usually be detected during testing or normal operation of the product.
Effectiveness: Opportunistic
Common questions about CWE-686.
Weakness data is sourced from the MITRE CWE catalog (v4.20). CVE associations are aggregated and kept current by RadicalNotion.AI.
Get alerted the moment a new CWE-686 vulnerability affects your stack, with AI-written analysis, severity context, and remediation guidance.