Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-341
Weakness type CWE-341 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 7 | 7 | 0 |
Monthly trend
▃▃▆█▁
2026-06 1 · 2026-07 1 · 2026-08 2 · 2026-09 3 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-38968 | 9.8 | 44.4 | — | — |
| CVE-2026-94456 | 9.1 | 42.5 | — | Unauthenticated recovery of the Math.random() state behind OAuth tokens, authorization … |
| CVE-2026-87912 | 5.1 | 36.3 | — | Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agent… |
| CVE-2026-87913 | 5.1 | 36.3 | — | Missing S3 bucket ownership verification in the AWS Security Agent MCP server |
| CVE-2026-15571 | 7.3 | 35.2 | — | Keycloak-services: keycloak-services: predictable account-linking hash enables account … |
| CVE-2026-19565 | 3.7 | 33.3 | — | Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session au… |
| CVE-2026-36609 | 7.3 | 12.7 | — | — |