Cyber Resilience

CWE · MITRE source

CWE-783Operator Precedence Logic Error

Abstraction: Base · CVEs in our corpus: 20

The product uses an expression in which operator precedence causes incorrect logic to be used.

While often just a bug, operator precedence logic errors can have serious consequences if they are used in security-critical code, such as making an authentication decision.

Last updated: 20 August 2026 13:14 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • SA-11 Developer Testing and Evaluation
  • SA-8 Security and Privacy Engineering Principles
  • SA-15 Development Process, Standards, and Tools
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-32896 KEV 8.57.80.03012024-06-13
CVE-2026-252336.89.10.00312026-02-03
CVE-2024-20314 6.48.60.00802024-03-27
CVE-2024-20480 6.38.60.00572024-09-25
CVE-2022-20477 5.67.80.00142022-12-13
CVE-2024-31326 5.67.80.00132024-07-09
CVE-2024-31335 5.67.80.00122024-07-09
CVE-2024-34741 5.67.80.00152024-08-15
CVE-2026-7270 5.67.80.00182026-04-30
CVE-2024-34720 5.57.80.00112024-07-09
CVE-2024-34723 5.57.80.00112024-07-09
CVE-2024-34726 5.57.80.00112024-07-09
CVE-2024-440935.47.80.00082024-09-13
CVE-2024-31331 5.27.30.00122024-07-09
CVE-2024-27886 4.45.50.00482024-07-29
CVE-2025-24210 4.35.50.00312025-03-31
CVE-2017-13322 4.25.50.00162025-01-17
CVE-2024-49736 4.05.50.00072025-01-21