Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) is the broad parent weakness for information disclosure findings and is a CWE Top 25…

What MITRE CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor requires

CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) is the broad parent weakness for information disclosure findings and is a CWE Top 25 weakness consistently associated with data breach incidents, security misconfiguration findings, and API leakage. CWE-200 is defined as: the product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. The Extended Description notes that information exposures vary widely in severity depending on context, the type of sensitive data revealed, and potential attacker benefits. Categories of sensitive information include personal data (messages, financial records, health information, location, contact details); system environment details (operating system, installed packages); trade secrets and intellectual property; network status and configuration; product code or internal state; metadata such as connection logs or message headers; and indirect information revealing discrepancies observable by outsiders. Different parties may have varying expectations about information protection: product users, individuals whose data is processed, administrators, and developers. Exposures occur through three primary mechanisms: (1) code explicitly inserting sensitive information into accessible resources without proper sanitization; (2) different weaknesses indirectly inserting sensitive data (such as system paths in error messages); and (3) resources containing sensitive information becoming unintentionally accessible due to separate vulnerabilities. Common Consequences include read application data with confidentiality scope. Potential Mitigations include architecture and design: employ separation of privilege strategies by compartmentalizing systems into safe areas with clear trust boundaries; prevent sensitive data from crossing trust boundaries and exercise caution when interfacing external compartments; build compartmentalization into system design reinforcing privilege separation using least privilege principles; determine appropriate times for privilege elevation and removal.

Pillar: Cybersecurity · Authority: MITRE Corporation / Common Weakness Enumeration · Version: 1.0.0 · Last updated:

Primary source: https://cwe.mitre.org/data/definitions/200.html

SHA-256 integrity: 90a1647c31ef0d9e93cc8288995713c2a8054071a2840dba4b48bd17cdff961b

Primary Citations — 10 traced to source

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor - MITRE Common Weakness Enumeration at https://cwe.mitre.org/data/definitions/200.html
  • CWE-200 Definition - the product exposes sensitive information to an actor that is not explicitly authorized to have access to that information

+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.