CWE-704: Incorrect Type Conversion or Cast
The product does not correctly convert an object, resource, or structure from one type to a different type.
Last updated
Overview
CWE-704 (Incorrect Type Conversion or Cast) is a class-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
75 recorded CVEs are caused by CWE-704 (Incorrect Type Conversion or Cast). The highest-severity and most recent are shown first. 23 new CWE-704 CVEs have been recorded so far in 2026 (10 in 2025).
- CVE-2026-15826
User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter
Critical · CVSS 9.8 · EPSS 90th2026-08-15 - CVE-2025-41648
Pilz: Authentication Bypass in IndustrialPI Webstatus
Critical · CVSS 9.8 · EPSS 51th2025-07-01 - CVE-2025-41646
RevPi Webstatus application is vulnerable to an authentication bypass