CWE-696: Incorrect Behavior Order
The product performs multiple related behaviors, but the behaviors are performed in the wrong order in ways that may produce resultant weaknesses.
39 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-44108 — Firewall bypass during shutdown
- CVE-2025-31485 — GraphQL grant on a property might be cached with different objects
- CVE-2026-40583 — UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt
- CVE-2024-24853 — Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Process
- CVE-2025-0150 — Zoom Workplace Apps for iOS - Incorrect Behavior Order
- CVE-2026-45033 — GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor
- CVE-2025-9904 — Unallocated memory access vulnerability in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Pr
- CVE-2025-55114 — BMC Control-M/Agent improper IP address filtering order
- CVE-2026-14169 — ads-tec Industrial IT: Account lockout via non-atomic user creation
- CVE-2026-35636 — OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolution
- CVE-2026-35652 — OpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback Dispatch
- CVE-2026-35640 — OpenClaw < 2026.3.25 - Denial of Service via Unauthenticated Webhook Request Parsing
- CVE-2026-35627 — OpenClaw < 2026.3.22 - Unauthenticated Cryptographic Work in Nostr Inbound DM Handling
- CVE-2026-67217 — cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation
- CVE-2026-35637 — OpenClaw < 2026.3.22 - Premature Cite Expansion Before Authorization in Channel and DM
- CVE-2026-68930 — Russh: Channel-scoped server callbacks can be reached without an open channel
- CVE-2026-33305 — OpenEMR has Authorization Bypass in FaxSMS AppDispatch Constructor
- CVE-2026-65100 — Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encode
- CVE-2025-20012 — Incorrect behavior order for some Intel(R) Core™ Ultra Processors may allow an unauthenticated user to potentially enabl
- CVE-2026-43002 — An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session stor
Recently published
- CVE-2026-68930 — Russh: Channel-scoped server callbacks can be reached without an open channel
- CVE-2026-44108 — Firewall bypass during shutdown
- CVE-2026-67217 — cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation
- CVE-2026-65100 — Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encode
- CVE-2026-14169 — ads-tec Industrial IT: Account lockout via non-atomic user creation
- CVE-2026-56355 — GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
- CVE-2026-49318 — Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at boot
- CVE-2026-49317 — Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at boot
- CVE-2026-44919 — In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can oc
- CVE-2026-45033 — GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor
- CVE-2026-44600 — Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue.
- CVE-2026-43002 — An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session stor
- CVE-2026-40583 — UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt
- CVE-2026-41254 — Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed
- CVE-2026-35652 — OpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback Dispatch
- CVE-2026-40223 — In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exi
- CVE-2026-35640 — OpenClaw < 2026.3.25 - Denial of Service via Unauthenticated Webhook Request Parsing
- CVE-2026-35637 — OpenClaw < 2026.3.22 - Premature Cite Expansion Before Authorization in Channel and DM
- CVE-2026-35636 — OpenClaw 2026.3.11 < 2026.3.25 - Session Isolation Bypass via sessionId Resolution
- CVE-2026-35627 — OpenClaw < 2026.3.22 - Unauthenticated Cryptographic Work in Nostr Inbound DM Handling
More specific weaknesses
- CWE-1190 — DMA Device Enabled Too Early in Boot Phase
- CWE-1193 — Power-On of Untrusted Execution Core Before Enabling Fabric Access Control
- CWE-1279 — Cryptographic Operations are run Before Supporting Units are Ready
- CWE-1280 — Access Control Check Implemented After Asset is Accessed
- CWE-179 — Incorrect Behavior Order: Early Validation
- CWE-408 — Incorrect Behavior Order: Early Amplification