Common Weakness Enumeration

    CWE Definition / CWE-296

    CWE-296: Improper Following of a Certificate's Chain of Trust

    The product does not follow, or incorrectly follows, the chain of trust for a certificate back to a trusted root certificate.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:30 Apr 2026

    Related Weakness

    CWE-295: Improper Certificate Validation

    CWE-573: Improper Following of Specification by Caller