CWE-708: Incorrect Ownership Assignment
The product assigns an owner to a resource, but the owner is outside of the intended control sphere.
Last updated
Overview
This may allow the resource to be manipulated by actors outside of the intended control sphere.
Real-world CVEs
20 recorded CVEs are caused by CWE-708 (Incorrect Ownership Assignment). The highest-severity and most recent are shown first. 2 new CWE-708 CVEs have been recorded so far in 2026 (6 in 2025).
- CVE-2026-40196
HomeBox has Unauthorized API Access via Retained defaultGroup ID After Group Access Revocation
High · CVSS 8.1 · EPSS 12th2026-04-17 - CVE-2021-32689
Nextcloud Talk not properly disassociating users from chats after account deletion
High · CVSS 8.1 · EPSS 50th2021-07-12 - CVE-2024-52561High · CVSS 7.8 · EPSS 40th2025-06-03