Falhas do tipo CWE-1188

213 resultados

Padrão inseguro não alterado pelo administrador

A aplicação é entregue com uma configuração padrão insegura (como senha padrão, porta aberta, ou função habilitada por padrão) que deveria ser mudada na primeira execução ou durante a administração, mas não é. O desenvolvedor assume que o admin vai mudar, mas isso frequentemente não acontece, deixando a falha na produção.

Exemplo

Um servidor de banco de dados instalado com usuário 'admin' e senha 'admin123' como padrão, documentado que deve ser alterado na primeira inicialização. Se o administrador pula essa etapa ou a ignora, qualquer um consegue acessar o banco com credenciais triviais.

Como mitigar

Force a mudança de configurações críticas na primeira execução (bloqueie a aplicação até que defaults inseguros sejam alterados), forneça valores padrão aleatórios e únicos por instalação, ou use setup assistido que não permite prosseguir sem trocar credenciais e permissões perigosas.

CVE-2026-93338MEDIUMGrandstream GWN7660ELR < 1.0.27.6 Information Disclosure via SNMP Default Community StringEPSS 0.3%CVE-2025-35021MEDIUMAbilis CPX Fallback Shell Connection RelayEPSS 0.3%CVE-2026-45728HIGHAlgernon: Single-file mode unconditionally enables debug modeEPSS 0.3%CVE-2026-63563MEDIUMSharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in EPSS 0.3%CVE-2025-64135MEDIUMJenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` EPSS 0.3%CVE-2025-53602MEDIUMZipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-2025-48927.EPSS 0.3%CVE-2026-6866HIGHInitialization of a Resource with an Insecure Default vulnerability on EcoStruxure™ Panel ServerEPSS 0.3%CVE-2026-32046MEDIUMOpenClaw < 2026.2.21 - OS-level Sandbox Bypass via --no-sandbox FlagEPSS 0.3%CVE-2025-25271HIGHOCPP Backend Configuration via Insecure DefaultsEPSS 0.3%CVE-2022-2196MEDIUMSpeculative execution attacks in KVM VMXEPSS 0.3%CVE-2026-53507HIGHoasdiff actions resolve external $refs by default, enabling SSRF and disclosure of structured files on pull-request runsEPSS 0.3%CVE-2025-61481CRITICALAn issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an oEPSS 0.3%CVE-2026-33376HIGHAuth Proxy IPv6 whitelist bypassEPSS 0.3%CVE-2026-49462MEDIUMnl.nl-portal:app has GraphiQL UI and GraphQL schema introspection enabled by defaultEPSS 0.3%CVE-2026-43527MEDIUMOpenClaw < 2026.4.14 - Server-Side Request Forgery via Private Network NavigationEPSS 0.3%CVE-2026-44892HIGHNetty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header SizeEPSS 0.3%CVE-2025-31930HIGHA vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions < V2.135), IEC 1Ph 7.4kW Child socket/ EPSS 0.3%CVE-2025-29985MEDIUMDell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Initialization of a Resource with an Insecure Default vulnerability in the EPSS 0.3%CVE-2026-9262HIGHUse of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlierEPSS 0.3%CVE-2026-43892HIGHAntSword: Incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injectionEPSS 0.3%