Cyber Resilience

CWE · MITRE source

CWE-1434Insecure Setting of Generative AI/ML Model Inference Parameters

Abstraction: Base · CVEs in our corpus: 4

The product has a component that relies on a generative AI/ML model configured with inference parameters that produce an unacceptably high rate of erroneous or unexpected outputs.

Generative AI/ML models, such as those used for text generation, image synthesis, and other creative tasks, rely on inference parameters that control model behavior, such as temperature, Top P, and Top K. These parameters affect the model's internal decision-making processes, learning rate, and probability distributions. Incorrect settings can lead to unusual behavior such as text "hallucinations," unrealistic images, or failure to converge during training. The impact of such misconfigurations can compromise the integrity of the application. If the results are used in security-critical operations or decisions, then this could violate the intended security policy, i.e., introduce a vulnerability.

Mapped by Cyber Resilience. This is an AI-native weakness the NVD catalog almost never assigns. We mapped 4 CVEs to it ourselves — a language-model classifier reads each CVE description and proposes the weakness, human-reviewed before it surfaces, with model poisoning and extraction cases deliberately routed to MITRE ATLAS rather than a synthetic CWE. The mappings are additive; NVD records are unchanged. Rows tagged CR below are ours.

Last updated: 11 August 2026 10:53 UTC

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-6331 CR5.97.50.00502024-08-04
CVE-2026-5817 CR5.78.20.00222026-05-22
CVE-2026-61439 CR5.77.50.00262026-07-11
CVE-2024-8939 CR4.76.20.00232024-09-17