CWE-1188: Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.
165 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-31957 — Himmelblau unset domain configuration can allow any-tenant authentication at first login for remote deployments
- CVE-2026-28775 — Unauthenticated RCE via SNMP Default Writable Community String
- CVE-2025-41672 — WAGO: Vulnerability in WAGO Device Sphere
- CVE-2024-0001 — A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active
- CVE-2025-62877 — Harvest may expose OS default ssh login password via SUSE Virtualization Interactive Installer
- CVE-2025-41438 — Consilium Safety CS5000 Fire Panel Initialization of a Resource with an Insecure Default
- CVE-2025-1960 — CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could cause an attacker to exe
- CVE-2025-1863 — Insecure default settings for recorder products
- CVE-2026-31818 — Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist
- CVE-2026-25894 — FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configuration
- CVE-2025-7353 — Rockwell Automation ControlLogix® Ethernet Remote Code Execution Vulnerability
- CVE-2025-59097 — Unauthenticated SOAP API in dormakaba access manager
- CVE-2025-59090 — Unauthenticated SOAP API in dormakaba Kaba exos 9300
- CVE-2025-54127 — HAXcms's Insecure Default Configuration Leads to Unauthenticated Access
- CVE-2025-48927 — The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heap
- CVE-2025-47945 — Donetick Has Weak Default JWT Secret
- CVE-2025-31930 — A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions < V2.135), IEC 1Ph
- CVE-2025-25271 — OCPP Backend Configuration via Insecure Defaults
- CVE-2026-54066 — SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)
- CVE-2018-25169 — AMPPS 2.7 Denial of Service via Malformed Socket Connection
Recently published
- CVE-2026-87827 — KGUARD DVR unauthenticated remote command execution vulnerability
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity
- CVE-2026-77348 — Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php`
- CVE-2026-53507 — oasdiff actions resolve external $refs by default, enabling SSRF and disclosure of structured files on pull-request runs
- CVE-2026-75062 — Eval Injection in google/langfun via default lf.query protocol
- CVE-2026-55581 — mcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
- CVE-2026-77915 — rConfig Core 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.php
- CVE-2026-62388 — NLTK before 3.10.0 Insecure Default Configuration in pathsec.py
- CVE-2026-75926 — Hugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCSS Child-Process Grant
- CVE-2026-33921 — Npcap driver installed without administrator-only access restriction on Windows in Arc before v2.7.0
- CVE-2026-62416 — Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, requir
- CVE-2026-63563 — Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication
- CVE-2026-67208 — Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console
- CVE-2026-66066 — Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
- CVE-2026-65881 — Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1
- CVE-2026-9680 — MCP Server Exposure via Insecure Default Binding on alibabacloud-rds-openapi-mcp-server
- CVE-2026-55708 — Privacy/configuration issue when adding local data in views through 'unbound-control'
- CVE-2026-47393 — PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
- CVE-2026-62415 — Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2
- CVE-2026-60024 — Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0
More specific weaknesses
- CWE-453 — Insecure Default Variable Initialization