Skip to main content

About CWE-200

The listed consequence is unauthorized reading of application data, with severity depending on what is revealed and how it helps an attacker.

MITRE marks CWE-200 as DISCOURAGED for mapping real-world vulnerabilities; map to the error that caused the disclosure.

MITRE name
Exposure of Sensitive Information to an Unauthorized Actor
Abstraction
Class: a very abstract weakness, typically independent of language or technology
Status
Draft
Also known as
Information Disclosure, Information Leak

Mitigations

  • +Compartmentalize the system with clear trust boundaries and keep sensitive data inside them.
  • +Apply least privilege when deciding when to use and when to drop privileges.
  • +Identify the specific error that disclosed the information and map to that weakness, such as CWE-201 or CWE-203.

Detection
MITRE lists web application and web services scanners as highly cost effective, with fuzzers and bytecode analysis giving partial coverage.

CWE-200 Vulnerabilities

9 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2025-68686
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Fortinet5.329.5%KEV2026-02-10
CVE-2025-31125
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
vitejs5.365.2%KEV2025-03-31
CVE-2026-20805
Desktop Window Manager Information Disclosure Vulnerability
Microsoft5.57.2%KEV2026-01-13
CVE-2021-41277
GeoJSON URL validation can expose server files and environment variables to unauthorized users
metabase10.097.2%KEV2021-11-17
CVE-2024-24919
Information disclosure
checkpoint8.6100.0%KEV2024-05-28
CVE-2020-3259
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability
Cisco7.571.8%KEV2020-05-06
CVE-2023-28432
Minio Information Disclosure in Cluster Deployment
minio7.584.0%KEV2023-03-22
CVE-2021-25369
Samsung Mobile Devices Improper Access Control Vulnerability
Samsung Mobile6.21.1%KEV2021-03-26
CVE-2022-20821
Cisco IOS XR Software Health Check Open Port Vulnerability
Cisco6.511.5%KEV2022-05-26

Frequently Asked Questions

What is CWE-200?→

CWE-200 is the exposure of sensitive information to an actor who is not authorized to access it.

Why does MITRE discourage CWE-200 for mapping?→

MITRE says it is often used to describe confidentiality loss, which is an impact rather than a root cause. As of CWE 4.9 over 400 entries can lead to that loss.

How many exploited vulnerabilities are classified as CWE-200?→

This database lists 9 CVE records mapped to CWE-200 by their CVE Numbering Authority. 9 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 2 to known ransomware campaigns. Examples include CVE-2025-68686, CVE-2025-31125, CVE-2026-20805.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.