Common Weakness Enumeration
CWE Definition / CWE-782
CWE-782: Exposed IOCTL with Insufficient Access Control
The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.
Published:15 Jul 2009
Organization:MITRE
Modified:11 Dec 2025
