Exposure of Sensitive Information (CWE-200)
CWE-200 covers products that expose sensitive information to an actor not explicitly authorized to see it. Examples include personal data, system configuration, business secrets and internal state. MITRE discourages mapping to it because loss of confidentiality is an impact that hundreds of other weaknesses can cause.
About CWE-200
The listed consequence is unauthorized reading of application data, with severity depending on what is revealed and how it helps an attacker.
MITRE marks CWE-200 as DISCOURAGED for mapping real-world vulnerabilities; map to the error that caused the disclosure.
Mitigations
- +Compartmentalize the system with clear trust boundaries and keep sensitive data inside them.
- +Apply least privilege when deciding when to use and when to drop privileges.
- +Identify the specific error that disclosed the information and map to that weakness, such as CWE-201 or CWE-203.
Detection
MITRE lists web application and web services scanners as highly cost effective, with fuzzers and bytecode analysis giving partial coverage.
CWE-200 Vulnerabilities
9 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2025-68686 | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | Fortinet | 5.3 | 29.5% | KEV | 2026-02-10 |
| CVE-2025-31125 | Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query | vitejs | 5.3 | 65.2% | KEV | 2025-03-31 |
| CVE-2026-20805 | Desktop Window Manager Information Disclosure Vulnerability | Microsoft | 5.5 | 7.2% | KEV | 2026-01-13 |
| CVE-2021-41277 | GeoJSON URL validation can expose server files and environment variables to unauthorized users | metabase | 10.0 | 97.2% | KEV | 2021-11-17 |
| CVE-2024-24919 | Information disclosure | checkpoint | 8.6 | 100.0% | KEV | 2024-05-28 |
| CVE-2020-3259 | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability | Cisco | 7.5 | 71.8% | KEV | 2020-05-06 |
| CVE-2023-28432 | Minio Information Disclosure in Cluster Deployment | minio | 7.5 | 84.0% | KEV | 2023-03-22 |
| CVE-2021-25369 | Samsung Mobile Devices Improper Access Control Vulnerability | Samsung Mobile | 6.2 | 1.1% | KEV | 2021-03-26 |
| CVE-2022-20821 | Cisco IOS XR Software Health Check Open Port Vulnerability | Cisco | 6.5 | 11.5% | KEV | 2022-05-26 |
Most Affected Vendors
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-200?→
CWE-200 is the exposure of sensitive information to an actor who is not authorized to access it.
Why does MITRE discourage CWE-200 for mapping?→
MITRE says it is often used to describe confidentiality loss, which is an impact rather than a root cause. As of CWE 4.9 over 400 entries can lead to that loss.
How many exploited vulnerabilities are classified as CWE-200?→
This database lists 9 CVE records mapped to CWE-200 by their CVE Numbering Authority. 9 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 2 to known ransomware campaigns. Examples include CVE-2025-68686, CVE-2025-31125, CVE-2026-20805.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.