Cyber Resilience

CWE · MITRE source

CWE-449The UI Performs the Wrong Action

Abstraction: Base · CVEs in our corpus: 14

The UI performs the wrong action with respect to the user's request.

Last updated: 20 August 2026 13:14 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 1 mapping(s) from 1 framework(s): STIG ubuntu 22 04 1 (partial)

See the full cumulative-coverage rollup →

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • SI-10 Information Input Validation
  • AC-3 Access Enforcement
  • SA-8 Security and Privacy Engineering Principles
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 1 hardening rule · 1 OS baseline
Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2023-36535 5.77.10.01242023-08-08
CVE-2023-39215 5.77.10.01122023-09-12
CVE-2023-43585 5.57.10.00602023-12-13
CVE-2023-39209 4.85.90.00962023-08-08
CVE-2025-266434.55.40.00692025-03-07
CVE-2025-56139 4.45.30.00332025-09-03
CVE-2024-24698 4.04.90.00532024-02-14
CVE-2024-49041 3.94.30.01072024-12-06
CVE-2025-214043.94.30.01072025-02-06
CVE-2024-38083 3.74.30.00492024-06-13
CVE-2024-43577 3.74.30.00462024-10-18
CVE-2025-49736 3.74.30.00492025-08-12
CVE-2025-136373.54.30.00202025-12-02
CVE-2023-43588 3.33.50.00652023-11-15