CWE-691: Insufficient Control Flow Management
The code does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.
Last updated
Overview
CWE-691 (Insufficient Control Flow Management) is a pillar-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
31 recorded CVEs are caused by CWE-691 (Insufficient Control Flow Management). The highest-severity and most recent are shown first. 1 new CWE-691 CVE has been recorded so far in 2026 (10 in 2025).