Weaknesses of type CWE-1188

215 results

Padrão inseguro que deveria ser alterado pelo administrador

O software sai da fábrica com configurações padrão inseguras (senhas fracas, portas abertas, protocolos desabilitados) que o administrador precisaria mudar manualmente. O problema é quando o desenvolvedor assume que essa mudança vai acontecer e não força o usuário a fazer isso na primeira execução, deixando sistemas desprotegidos em produção.

Example

Um servidor web vem com credenciais padrão (admin/admin) e a documentação diz 'altere na primeira inicialização'. Mas o admin esquece ou não lê, e o sistema fica acessível com essas credenciais conhecidas publicamente, permitindo invasão imediata.

How to mitigate

Force a mudança de configurações críticas na primeira inicialização (modo setup obrigatório), gere padrões fortes automaticamente (senhas aleatórias) ou desabilite recursos perigosos por padrão, exigindo ativação explícita do admin com reconhecimento dos riscos.

CVE-2026-6043HIGHInsecure Default Configuration in P4 ServerEPSS 1.3%CVE-2025-59090CRITICALUnauthenticated SOAP API in dormakaba Kaba exos 9300EPSS 1.2%CVE-2022-31806CRITICALInsecure default settings in CODESYS Runtime Toolkit 32 bit full and CODESYS PLCWinNTEPSS 1.2%CVE-2026-28775CRITICALUnauthenticated RCE via SNMP Default Writable Community StringEPSS 1.2%CVE-2023-31101—Apache InLong: Users who joined later can see the data of deleted usersEPSS 1.1%CVE-2026-87827CRITICALKGUARD DVR unauthenticated remote command execution vulnerabilityEPSS 1.1%CVE-2017-12736HIGHAfter initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to write to the device under certain conditions. This EPSS 1.1%CVE-2025-2129MEDIUMMage AI insecure default initialization of resourceEPSS 1.0%CVE-2024-50390HIGHQHoraEPSS 1.0%CVE-2026-26122MEDIUMMicrosoft ACI Confidential Containers Information Disclosure VulnerabilityEPSS 1.0%CVE-2021-3586—A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accesEPSS 1.0%CVE-2024-0001CRITICALA condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowingEPSS 0.9%CVE-2026-50519MEDIUMMicrosoft Visual Studio Code CoPilot Chat Security Feature Bypass VulnerabilityEPSS 0.9%CVE-2024-28815CRITICALA vulnerability in the BluStar component of Mitel InAttend 2.6 SP4 through 2.7 and CMG 8.5 SP4 through 8.6 could allow access to sensitive iEPSS 0.9%CVE-2026-57127CRITICALpraisonai: recipe serve auth middleware silently disables itself when no secret is setEPSS 0.9%CVE-2022-4224HIGHCODESYS: Exposure of Resource to Wrong Sphere in CODESYS V3EPSS 0.9%CVE-2022-38745HIGHApache OpenOffice: Empty entry in Java class pathEPSS 0.9%CVE-2022-32480MEDIUMDell PowerScale OneFS, versions 9.0.0, up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an insecure default initializatEPSS 0.9%CVE-2022-1278—A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.EPSS 0.9%CVE-2026-41432HIGHNew API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota FraudEPSS 0.9%