Weaknesses of type CWE-1188

214 results

Padrão inseguro que deveria ser alterado pelo administrador

O software sai da fábrica com configurações padrão inseguras (senhas fracas, portas abertas, protocolos desabilitados) que o administrador precisaria mudar manualmente. O problema é quando o desenvolvedor assume que essa mudança vai acontecer e não força o usuário a fazer isso na primeira execução, deixando sistemas desprotegidos em produção.

Example

Um servidor web vem com credenciais padrão (admin/admin) e a documentação diz 'altere na primeira inicialização'. Mas o admin esquece ou não lê, e o sistema fica acessível com essas credenciais conhecidas publicamente, permitindo invasão imediata.

How to mitigate

Force a mudança de configurações críticas na primeira inicialização (modo setup obrigatório), gere padrões fortes automaticamente (senhas aleatórias) ou desabilite recursos perigosos por padrão, exigindo ativação explícita do admin com reconhecimento dos riscos.

CVE-2026-44588CRITICALSiYuan: URL-encoded title bypasses `escapeAriaLabel`, decoded by `decodeURIComponent` into a tooltip-XSSEPSS 0.5%CVE-2025-1960CRITICALCWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could cause an attacker to execute unauthorized coEPSS 0.5%CVE-2026-31957CRITICALHimmelblau unset domain configuration can allow any-tenant authentication at first login for remote deploymentsEPSS 0.5%CVE-2025-22248CRITICAL[pgpool] Unauthenticated access to postgres through pgpoolEPSS 0.5%CVE-2026-46386CRITICALOpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`EPSS 0.5%CVE-2019-25219HIGHAsio C++ Library before 1.13.0 lacks a fallback error code in the case of SSL_ERROR_SYSCALL with no associated error information from the SSEPSS 0.5%CVE-2025-69970CRITICALFUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented ouEPSS 0.5%CVE-2026-56285HIGHNitter - Server-Side Request Forgery in /video Media Proxy EndpointEPSS 0.5%CVE-2023-40708MEDIUMImproper Access Control in OPTO 22 SNAP PAC S1EPSS 0.5%CVE-2026-89139HIGHTemporal Server worker deployment compute provider executes a caller-supplied command on the Worker Service hostEPSS 0.5%CVE-2023-28978MEDIUMJunos OS Evolved: Read access to some confidential user information is possibleEPSS 0.5%CVE-2025-24288CRITICALThe Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multEPSS 0.5%CVE-2026-61793MEDIUMNuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameterEPSS 0.5%CVE-2026-62185HIGHArgo CD Helm Chart < 10.0.0 Missing Network Policy RCEEPSS 0.5%CVE-2026-62388HIGHNLTK before 3.10.0 Insecure Default Configuration in pathsec.pyEPSS 0.5%CVE-2026-34742HIGHModel Context Protocol Go SDK: DNS Rebinding Protection Disabled by Default for Servers Running on LocalhostEPSS 0.5%CVE-2025-46599MEDIUMCNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that, in some situations,EPSS 0.5%CVE-2026-28205CRITICALInitialization of a resource with an insecure default in OpenPLC_V3EPSS 0.4%CVE-2026-25499HIGHterraform-provider-proxmox has insecure sudo recommendation in the documentationEPSS 0.4%CVE-2026-62415CRITICALJoomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2EPSS 0.4%