Common Weakness Enumeration

    CWE Definition / CWE-1386

    CWE-1386: Insecure Operation on Windows Junction / Mount Point

    The product opens a file or directory, but it does not properly prevent the name from being associated with a junction or mount point to a destination that is outside of the intended control sphere.

    Published:7 Jun 2022
    Organization:MITRE
    Modified:30 Apr 2026

    Related Weakness

    CWE-59: Improper Link Resolution Before File Access ('Link Following')

    CWE-1386: Insecure Operation on Windows Junction / Mount… | CVE-DB