CWE-1188

Initialization of a Resource with an Insecure Default

Parent: CWE-1419 - Incorrect Initialization of Resource

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

312 vulnerabilities with CWE-1188
CVE-2026-67208 CRITICAL
Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console
CVSS 9.8
CVE-2026-66066 CRITICAL
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
CVE-2026-65881 HIGH
Joomdle < 3.1.1 - Insecure Defaults Allow CMS Account Access
CVSS 7.5
CVE-2026-9680 MEDIUM
MCP Server Exposure via Insecure Default Binding on alibabacloud-rds-openapi-mcp-server
CVSS 5.8
CVE-2026-47668 CRITICAL
DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
CVSS 10.0
CVE-2026-55708 LOW
Privacy/configuration issue when adding local data in views through 'unbound-control'
CVSS 3.1
CVE-2026-47393 CRITICAL
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
CVSS 9.8
CVE-2026-62415 CRITICAL
Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2
CVSS 9.1
CVE-2026-60024 CRITICAL
Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0
CVSS 9.8
CVE-2026-62185 HIGH
Argo CD Helm Chart < 10.0.0 Missing Network Policy RCE
CVSS 7.6
CVE-2026-61439 HIGH
PraisonAI before 4.6.78 Prompt Injection Defense Bypass
CVSS 7.5
CVE-2026-54800 MEDIUM
Siemens CPCI85 Central Processing/Communication - Initialization of a Resource with an Insecure Default
CVSS 4.8
CVE-2026-14474 HIGH
Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by default, enabling privilege escalation
CVSS 8.8
CVE-2026-56285 HIGH
Nitter - Server-Side Request Forgery in /video Media Proxy Endpoint
CVSS 8.6
CVE-2026-46386 CRITICAL
OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`
CVSS 9.9
CVE-2026-55454 CRITICAL
Appsmith: Caddy admin API exposed without authentication
CVSS 9.9
CVE-2026-54158 CRITICAL
SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
CVSS 9.9
CVE-2026-54067 CRITICAL
SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
CVSS 9.9
CVE-2026-54066 HIGH
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)
CVSS 7.5
CVE-2026-48509 CRITICAL
MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies
CVSS 9.1
CVE-2026-48502 HIGH
MessagePack-CSharp ReadDateTime - Stack Overflow Denial of Service
CVSS 7.5
CVE-2026-50519 MEDIUM
Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability
CVSS 6.5
CVE-2026-20265 MEDIUM
Insecure Default Domain Allowlist in Splunk AI Toolkit
CVSS 4.3
CVE-2026-0134 LOW
Google Android - Information Disclosure
CVSS 3.3
CVE-2026-9262 MEDIUM
Canon Inc. Eos Network Setting Tool For Windows - Initialization of a Resource with an Insecure Default
CVSS 6.5
Details
Vulnerabilities 312