Common Weakness Enumeration

    CWE Definition / CWE-1270

    CWE-1270: Generation of Incorrect Security Tokens

    The product implements a Security Token mechanism to differentiate what actions are allowed or disallowed when a transaction originates from an entity. However, the Security Tokens generated in the system are incorrect.

    Published:6 Mar 2020
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-284: Improper Access Control

    CWE-1294: Insecure Security Identifier Mechanism