CWE-694: Use of Multiple Resources with Duplicate Identifier
The product uses multiple resources that can have the same identifier, in a context in which unique identifiers are required.
Last updated
Overview
If the product assumes that each resource has a unique identifier, the product could operate on the wrong resource if attackers can cause multiple resources to be associated with the same identifier.
Real-world CVEs
9 recorded CVEs are caused by CWE-694 (Use of Multiple Resources with Duplicate Identifier). The highest-severity and most recent are shown first. 3 new CWE-694 CVEs have been recorded so far in 2026 (2 in 2025).
- CVE-2025-13609
Keylime: keylime: registrar allows identity takeover via duplicate uuid registration
High · CVSS 8.2 · EPSS 37th2025-11-24 - CVE-2025-59048
OpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth Method
High · CVSS 8.1 · EPSS 16th2025-10-23 - CVE-2026-71327
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
High · CVSS 7.6 · EPSS 29th