CWE-1188

Initialization of a Resource with an Insecure Default

Parent: CWE-1419 - Incorrect Initialization of Resource

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

288 vulnerabilities with CWE-1188
CVE-2026-9262 MEDIUM
Canon Inc. Eos Network Setting Tool For Windows - Initialization of a Resource with an Insecure Default
CVSS 6.5
CVE-2026-54359 HIGH
MISP automation endpoints may be exposed to CSRF when Sec-Fetch-Site protection is disabled by default
CVE-2026-44892 HIGH
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
CVSS 7.5
CVE-2026-40994 HIGH
Spring Web Services - Wss4jSecurityInterceptor Disables WS-I BSP Validation by Default
CVSS 8.2
CVE-2026-46517 HIGH
LMDeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
CVSS 7.8
CVE-2026-36616 MEDIUM
Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909 - Hardcoded WiFi Driver Credentials Exposure
CVSS 5.9
CVE-2026-36612 MEDIUM
Mercusys AC12G (EU) V1 Firmware AC12G(EU)_V1_200909 - Weak WPS Lockout Policy
CVSS 6.4
CVE-2026-44825 HIGH
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
CVSS 8.1
CVE-2026-9039 HIGH
Initialization of a resource with an insecure default in XCharge C6
CVE-2026-35672 HIGH
phpMyFAQ - Authentication Bypass via Empty API Token
CVSS 7.5
CVE-2026-24197 MEDIUM
Nvidia GeForce - Initialization of a Resource with an Insecure Default
CVSS 6.5
CVE-2026-46430 MEDIUM
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS
CVSS 4.3
CVE-2026-45728 HIGH
Algernon: Single-file mode unconditionally enables debug mode
CVSS 7.5
CVE-2026-44670 CRITICAL
SiYuan: Stored XSS via Attribute View name to Electron renderer RCE in SiYuan
CVE-2026-44588 CRITICAL
SiYuan: URL-encoded title bypasses `escapeAriaLabel`, decoded by `decodeURIComponent` into a tooltip-XSS
CVE-2026-33376 HIGH
Grafana OSS Insecure Default IPv6 Allow-List Mask in Auth Proxy
CVSS 7.4
CVE-2026-43892 HIGH
AntSword: Incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injection
CVSS 8.8
CVE-2026-30805 CRITICAL
Insecure Default Initialization in API Authentication leads to Authentication Bypass
CVSS 9.1
CVE-2026-6866 HIGH
Initialization of a Resource with an Insecure Default vulnerability on EcoStruxure™ Panel Server
CVE-2026-27662 HIGH
Siemens Simatic Hmi MTP1000 Unified Comfort Panel - Initialization of a Resource with an Insecure Default
CVSS 7.7
CVE-2026-41432 HIGH
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud
CVSS 7.1
CVE-2026-44338 HIGH
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
CVSS 7.3
CVE-2026-44109 CRITICAL
OpenClaw < 2026.4.15 - Authentication Bypass in Feishu Webhook and Card-Action Validation
CVSS 9.8
CVE-2026-43581 CRITICAL
OpenClaw < 2026.4.10 - Chrome DevTools Protocol Exposure via Overly Broad CDP Relay Binding
CVSS 9.6
CVE-2026-41931 MEDIUM
Vvveb < 1.0.8.2 Information Disclosure via Debug Exception Handler
CVSS 5.3
Details
Vulnerabilities 288