Common Weakness Enumeration

    CWE Definition / CWE-612

    CWE-612: Improper Authorization of Index Containing Sensitive Information

    The product creates a search index of private or sensitive documents, but it does not properly limit index access to actors who are authorized to see the original information.

    Published:7 May 2007
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-1230: Exposure of Sensitive Information Through Metadata