CWE-841: Improper Enforcement of Behavioral Workflow
The product supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.
66 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-0410 — Improper Enforcement of Behavioral Workflow in GitLab
- CVE-2026-79083 — Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker w
- CVE-2025-48479 — FreeScout Has Business Logic Errors
- CVE-2024-51738 — Sunshine improperly enforces pairing protocol request order
- CVE-2026-43937 — YAF.NET: Pre-Handler Authorization Bypass on Admin Pages Enabling Blind SQL Execution via `/Admin/RunSql`
- CVE-2026-55763 — Klever-Go: Percentage-transfer royalty skips the source debit at exactly-100% splits
- CVE-2026-34582 — Botan has a TLS 1.3 certificate authentication bypass
- CVE-2026-80195 — Kimai before 2.63.0 Team Membership Removal via API
- CVE-2026-43974 — gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM
- CVE-2025-52469 — Chamilo: Friend Request Workflow Bypass - Unauthorized Friend Addition and ID Validation Bypass
- CVE-2025-48477 — FreeScout Has Business Logic Errors
- CVE-2025-48476 — FreeScout Has Business Logic Errors
- CVE-2025-48480 — FreeScout Has Business Logic Errors
- CVE-2025-48478 — FreeScout Has Business Logic Errors
- CVE-2026-41259 — Mastodon: Insufficient verification of email addresses
- CVE-2025-58051 — Nextcloud Tables app allowed to include local file via PhpSpreadsheet when importing a table
- CVE-2026-42246 — net-imap vulnerable to STARTTLS stripping via invalid response timing
- CVE-2026-48505 — Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission
- CVE-2025-48481 — FreeScout Has Business Logic Errors
- CVE-2024-12543 — A user enumeration and subsequent data integrity vulnerability affecting barcode functionality
Recently published
- CVE-2026-87503 — Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacke
- CVE-2026-53637 — Sylius: Cart FormComponent allows modification or deletion of an already-completed order
- CVE-2026-67279 — SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS
- CVE-2026-82423 — macrozheng mall Payment Status Endpoint paySuccess behavioral workflow
- CVE-2026-55763 — Klever-Go: Percentage-transfer royalty skips the source debit at exactly-100% splits
- CVE-2026-78103 — Dimension Log Server Configuration Lock Bypass Vulnerability
- CVE-2026-78618 — Dimension Business Logic Flaw Allows Chained Backend Object Operations
- CVE-2026-77508 — Weblate: Unverified REST API email changes
- CVE-2026-15365 — A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass password verification and use Quick Apps ou
- CVE-2026-80195 — Kimai before 2.63.0 Team Membership Removal via API
- CVE-2026-79083 — Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker w
- CVE-2026-75081 — Webkul Bagisto store behavioral workflow
- CVE-2026-19993 — Webkul Bagisto RMA State Validation update-status behavioral workflow
- CVE-2026-19213 — WonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflow
- CVE-2026-19208 — WonderTrader TraderDD.cpp queryTrades behavioral workflow
- CVE-2026-19037 — WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behavioral workflow
- CVE-2026-18029 — Insufficient validation of payment status in pretix-girosolution
- CVE-2025-36333 — Vulnerabilities found in Watson Data Intelligence
- CVE-2026-57536 — Insufficient validation of payment status in pretix-mollie
- CVE-2026-13222 — Insufficient validation of payment status in pretix-oppwa