Cyber Resilience

CWE · MITRE source

CWE-708Incorrect Ownership Assignment

Abstraction: Base · CVEs in our corpus: 21

The product assigns an owner to a resource, but the owner is outside of the intended control sphere.

This may allow the resource to be manipulated by actors outside of the intended control sphere.

Last updated: 21 August 2026 14:15 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 1 mapping(s) from 1 framework(s): STIG rhel 7 1 (mostly)

See the full cumulative-coverage rollup →

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.AA-05
  • AC-3 Access Enforcement
  • AC-16 Security and Privacy Attributes
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 4 hardening rules · 3 OS baselines
Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2021-32689 6.38.10.01002021-07-12
CVE-2022-33737 6.07.50.00832022-07-06
CVE-2026-401966.08.10.00252026-04-17
CVE-2021-32726 5.87.10.01782021-07-12
CVE-2024-52561 5.77.80.00242025-06-03
CVE-2022-22189 5.47.30.00232022-04-14
CVE-2023-20043 5.06.70.00212023-01-20
CVE-2024-417735.06.50.00282024-08-20
CVE-2023-20044 4.96.70.00142023-01-20
CVE-2023-29122 4.96.70.00172024-11-05
CVE-2023-4008 4.65.30.00702023-08-03
CVE-2024-454174.56.00.00182025-02-25
CVE-2021-26248 4.25.50.00232021-11-19
CVE-2026-326914.15.30.00232026-03-18
CVE-2024-45426 3.94.90.00302025-02-25
CVE-2025-14262 3.54.30.00182025-12-08
CVE-2026-64693.23.80.00322026-08-13
CVE-2025-50693.13.50.00232025-09-26
CVE-2023-41881 3.03.70.00322023-10-11
CVE-2024-9633 2.93.10.00462024-11-14
CVE-2025-54672.83.30.00172025-12-10