What is CWE-506?
MITRE CWEThe product contains code that appears to be malicious in nature.
Verify to analyze this CWE entry
A short verification protects the official data source and prevents automated AI abuse.
The product contains code that appears to be malicious in nature.
A short verification protects the official data source and prevents automated AI abuse.
Original source fields and evidence from the MITRE CWE record.
The product contains code that appears to be malicious in nature.
Malicious flaws have acquired colorful names, including Trojan horse, trapdoor, timebomb, and logic-bomb. A developer might insert malicious code with the intent to subvert the security of a product or its host system at some time in the future. It generally refers to a program that performs a useful service but exploits rights of the program's user in a way the user does not intend.
Confidentiality, Integrity, Availability
Execute Unauthorized Code or Commands
These examples illustrate this CWE entry and are not an exhaustive list of related vulnerabilities.
CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
en