CWE-636: Failing Open
When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.
51 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-22034 — Snuffleupagus vulnerable to RCE on instances with upload validation enabled but without the VLD package
- CVE-2025-54870 — VTun-ng's failure to initialize encryption modules may cause reversion to plaintext
- CVE-2026-53913 — Apache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration the token is never verified and any non-null bearer value is accepted
- CVE-2026-73421 — NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
- CVE-2026-40525 — OpenViking < 0.3.9 Authentication Bypass via VikingBot OpenAPI
- CVE-2026-70452 — rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure
- CVE-2026-18329 — NGINX ngx_http_js_module vulnerability
- CVE-2026-40248 — free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions
- CVE-2026-40247 — free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions
- CVE-2026-35205 — Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
- CVE-2026-44094 — Fallback to second RAUC slot with default credentials
- CVE-2026-54291 — Silent channel-binding authentication downgrade via unsupported certificate algorithms
- CVE-2026-53712 — SCRAM: Silent channel-binding authentication downgrade via unsupported certificate algorithms
- CVE-2026-85649 — (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the A
- CVE-2026-68746 — Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access
- CVE-2026-42423 — OpenClaw < 2026.4.8 - strictInlineEval Approval Boundary Bypass via Approval-Timeout Fallback
- CVE-2026-42246 — net-imap vulnerable to STARTTLS stripping via invalid response timing
- CVE-2026-35042 — fast-jwt accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)
- CVE-2026-41334 — OpenClaw < 2026.3.31 - Decompression Bomb Denial of Service via Image Pixel-Limit Guard Bypass
- CVE-2026-40249 — free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors
Recently published
- CVE-2026-86120 — APITable through 1.13.0-beta.1 Fail-Open Authorization in the Fusion API Node Permission Guard
- CVE-2026-85649 — (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the A
- CVE-2026-18329 — NGINX ngx_http_js_module vulnerability
- CVE-2026-82744 — Ash.Reactor change step fails open, skipping a change when its where guard raises
- CVE-2026-82018 — IGEL OS 12 / 11 Secure Boot Bypass via Unsigned igel.conf File
- CVE-2026-46482 — MyBB: Security Question insufficient validation
- CVE-2026-73421 — NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
- CVE-2026-70452 — rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure
- CVE-2026-68746 — Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access
- CVE-2026-44094 — Fallback to second RAUC slot with default credentials
- CVE-2026-53712 — SCRAM: Silent channel-binding authentication downgrade via unsupported certificate algorithms
- CVE-2026-62235 — Grav Flex-Objects < 1.4.3 Authorization Bypass via API
- CVE-2026-54291 — Silent channel-binding authentication downgrade via unsupported certificate algorithms
- CVE-2026-53913 — Apache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration the token is never verified and any non-null bearer value is accepted
- CVE-2026-54762 — Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
- CVE-2026-55568 — Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
- CVE-2026-53852 — OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing
- CVE-2026-53837 — OpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event Handlers
- CVE-2026-49318 — Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at boot
- CVE-2026-49317 — Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at boot