Common Weakness Enumeration
CWE Definition / CWE-1386
CWE-1386: Insecure Operation on Windows Junction / Mount Point
The product opens a file or directory, but it does not properly prevent the name from being associated with a junction or mount point to a destination that is outside of the intended control sphere.
Published:7 Jun 2022
Organization:MITRE
Modified:30 Apr 2026
Related Weakness
CWE-59: Improper Link Resolution Before File Access ('Link Following')
