Cyber Resilience

CWE · MITRE source

CWE-424Improper Protection of Alternate Path

Abstraction: Class · CVEs in our corpus: 35

The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.

Last updated: 20 August 2026 13:14 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 6 mapping(s) from 5 framework(s): CAPEC 2 (partial) · STIG oracle linux 9 1 (partial) · STIG rhel 9 1 (partial) · STIG ubuntu 22 04 1 (partial) · STIG ubuntu 24 04 1 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A01:2025 Broken Access Control.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • AC-17 Remote Access
  • PR.AA-05
  • PR.IR-01
  • AC-3 Access Enforcement
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 6 hardening rules · 4 OS baselines
Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (1)AI-assisted

Control Title Family Why it addresses this CWE
AC-17Remote AccessACDocumenting requirements and authorizing remote access ensures proper protection of alternate paths.

MITRE ATT&CK techniques this weakness enables

Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2025-48827 9.910.00.77462025-05-27
CVE-2024-58136 KEV 8.99.00.84642025-04-10
CVE-2025-48828 8.69.00.60402025-05-27
CVE-2026-66756 7.39.80.00442026-07-30
CVE-2024-3459 6.28.40.00272024-05-14
CVE-2023-52952 5.88.50.00172024-10-08
CVE-2025-68939 5.88.20.00312025-12-26
CVE-2026-544235.88.20.00302026-07-10
CVE-2026-0237 5.67.80.00152026-05-13
CVE-2024-3460 5.57.40.00272024-05-14
CVE-2021-3793 5.36.50.00672021-11-12
CVE-2023-5165 5.37.10.00222023-09-25
CVE-2023-20272 5.36.70.00892023-11-21
CVE-2019-18996 5.27.10.00402019-12-18
CVE-2023-0629 5.27.10.00222023-03-13
CVE-2024-8311 5.26.50.00612024-09-12
CVE-2022-1742 5.16.80.00282022-06-24
CVE-2026-584285.06.50.00332026-08-13
CVE-2023-46176 4.96.70.00182023-11-03
CVE-2025-49163 4.96.70.00142025-06-03
CVE-2025-6250 4.96.70.00162025-07-28
CVE-2025-49162 4.76.40.00162025-06-03
CVE-2026-49134.75.70.00592026-04-14
CVE-2024-3927 4.45.30.00432024-05-22
CVE-2026-4270 4.15.50.00132026-03-16