CWE · MITRE source
CWE-669Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
Last updated: 20 August 2026 13:14 UTC
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
Prevent
Stop it (NIST 800-53 / CSF Protect)
Detect
Catch it (CSF Detect / Respond)
—
Harden
Shrink the surface (DISA STIG)
- 2 hardening rules · 2 OS baselines
Validate
Prove the fix (OWASP ASVS)
—
NIST 800-53 r5 controls that address this weakness (5)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
SC-32 | System Partitioning | SC | Reduces incorrect transfers between spheres by establishing clear, separate domains for different sensitivities or functions. |
SC-46 | Cross Domain Policy Enforcement | SC | It governs all resource transfers between spheres, preventing incorrect or unauthorized movement of data or capabilities across domain interfaces. |
AC-4 | Information Flow Enforcement | AC | Enforces proper authorization rules for any resource or data transfer between different spheres. |
MP-5 | Media Transport | MP | Accountability, documentation, and protection requirements ensure correct transfer of media resources between spheres. |
SR-12 | Component Disposal | SR | Addresses incorrect transfer of resources to an uncontrolled sphere by requiring approved destruction or sanitization methods. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2026-31431 KEV UPD | 8.5 | 7.8 | 0.9991 | 2026-04-22 |
CVE-2021-22900 KEV UPD | 8.1 | 7.2 | 0.1415 | 2021-05-27 |
CVE-2016-5062 UPD | 7.9 | 9.8 | 0.0393 | 2016-09-29 |
CVE-2019-13025 UPD | 7.8 | 9.8 | 0.0332 | 2019-10-02 |
CVE-2020-15892 UPD | 7.6 | 9.8 | 0.0164 | 2020-07-22 |
CVE-2020-5800 UPD | 7.6 | 9.8 | 0.0156 | 2020-12-07 |
CVE-2020-24683 UPD | 7.6 | 9.8 | 0.0146 | 2020-12-22 |
CVE-2021-30120 UPD | 7.6 | 9.9 | 0.0570 | 2021-07-09 |
CVE-2022-4446 UPD | 7.5 | 9.8 | 0.0127 | 2022-12-13 |
CVE-2025-67895 | 7.5 | 9.8 | 0.0098 | 2025-12-17 |
CVE-2026-25253 UPD | 7.4 | 8.8 | 0.0802 | 2026-02-01 |
CVE-2022-20658 UPD | 7.1 | 9.6 | 0.0139 | 2022-01-14 |
CVE-2019-11875 UPD | 7.0 | 8.8 | 0.0227 | 2019-05-24 |
CVE-2020-1048 UPD | 7.0 | 7.8 | 0.1650 | 2020-05-21 |
CVE-2023-31114 UPD | 6.9 | 9.1 | 0.0056 | 2023-06-07 |
CVE-2019-13263 UPD | 6.8 | 8.8 | 0.0117 | 2019-08-27 |
CVE-2020-25917 UPD | 6.8 | 8.8 | 0.0124 | 2020-12-26 |
CVE-2021-24602 UPD | 6.8 | 8.8 | 0.0151 | 2021-08-23 |
CVE-2021-45891 UPD | 6.8 | 8.8 | 0.0140 | 2022-04-05 |
CVE-2019-13266 UPD | 6.7 | 8.8 | 0.0097 | 2019-08-27 |
CVE-2025-41660 | 6.5 | 8.8 | 0.0043 | 2026-03-24 |
CVE-2019-11770 UPD | 6.4 | 8.1 | 0.0127 | 2019-06-14 |
CVE-2022-30236 UPD | 6.4 | 8.2 | 0.0077 | 2022-06-02 |
CVE-2018-17791 UPD | 6.2 | 7.5 | 0.0191 | 2019-08-21 |
CVE-2012-2979 UPD | 6.2 | 7.5 | 0.0174 | 2019-11-01 |