CWE · MITRE source
CWE-424Improper Protection of Alternate Path
The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.
Last updated: 20 August 2026 13:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 6 mapping(s) from 5 framework(s): CAPEC 2 (partial) · STIG oracle linux 9 1 (partial) · STIG rhel 9 1 (partial) · STIG ubuntu 22 04 1 (partial) · STIG ubuntu 24 04 1 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A01:2025 Broken Access Control.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (1)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
AC-17 | Remote Access | AC | Documenting requirements and authorizing remote access ensures proper protection of alternate paths. |
MITRE ATT&CK techniques this weakness enables
Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2025-48827 UPD | 9.9 | 10.0 | 0.7746 | 2025-05-27 |
CVE-2024-58136 KEV UPD | 8.9 | 9.0 | 0.8464 | 2025-04-10 |
CVE-2025-48828 UPD | 8.6 | 9.0 | 0.6040 | 2025-05-27 |
CVE-2026-66756 UPD | 7.3 | 9.8 | 0.0044 | 2026-07-30 |
CVE-2024-3459 UPD | 6.2 | 8.4 | 0.0027 | 2024-05-14 |
CVE-2023-52952 UPD | 5.8 | 8.5 | 0.0017 | 2024-10-08 |
CVE-2025-68939 UPD | 5.8 | 8.2 | 0.0031 | 2025-12-26 |
CVE-2026-54423 | 5.8 | 8.2 | 0.0030 | 2026-07-10 |
CVE-2026-0237 UPD | 5.6 | 7.8 | 0.0015 | 2026-05-13 |
CVE-2024-3460 UPD | 5.5 | 7.4 | 0.0027 | 2024-05-14 |
CVE-2021-3793 UPD | 5.3 | 6.5 | 0.0067 | 2021-11-12 |
CVE-2023-5165 UPD | 5.3 | 7.1 | 0.0022 | 2023-09-25 |
CVE-2023-20272 UPD | 5.3 | 6.7 | 0.0089 | 2023-11-21 |
CVE-2019-18996 UPD | 5.2 | 7.1 | 0.0040 | 2019-12-18 |
CVE-2023-0629 UPD | 5.2 | 7.1 | 0.0022 | 2023-03-13 |
CVE-2024-8311 UPD | 5.2 | 6.5 | 0.0061 | 2024-09-12 |
CVE-2022-1742 UPD | 5.1 | 6.8 | 0.0028 | 2022-06-24 |
CVE-2026-58428 | 5.0 | 6.5 | 0.0033 | 2026-08-13 |
CVE-2023-46176 UPD | 4.9 | 6.7 | 0.0018 | 2023-11-03 |
CVE-2025-49163 UPD | 4.9 | 6.7 | 0.0014 | 2025-06-03 |
CVE-2025-6250 UPD | 4.9 | 6.7 | 0.0016 | 2025-07-28 |
CVE-2025-49162 UPD | 4.7 | 6.4 | 0.0016 | 2025-06-03 |
CVE-2026-4913 | 4.7 | 5.7 | 0.0059 | 2026-04-14 |
CVE-2024-3927 UPD | 4.4 | 5.3 | 0.0043 | 2024-05-22 |
CVE-2026-4270 UPD | 4.1 | 5.5 | 0.0013 | 2026-03-16 |