When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.
Volume of CVEs assigned to CWE-636 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-53913CRITICAL Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component.
The KeycloakSecurity | Jul 6, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-50528HIGH Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. | Jul 14, 2026 | 8.2 | 36 | NO | NO |
CVE-2026-53712HIGH SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication mechanisms. Prior to 3. | Jul 17, 2026 | 8.2 | 35 | NO | NO |
CVE-2026-54762HIGH Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerability in Traefik's Kubernetes Ingress NGINX provider that causes | Jun 23, 2026 | 8.6 | 35 | NO | NO |
CVE-2024-43532HIGH Remote Registry Service Elevation of Privilege Vulnerability | Oct 8, 2024 | 8.8 | 34 | NO | NO |
CVE-2026-42246HIGH Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cau | May 9, 2026 | 7.4 | 33 | NO | NO |
CVE-2026-40525CRITICAL OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authentication check fails open when the api | Apr 17, 2026 | 9.1 | 33 | NO | NO |
CVE-2026-54291MEDIUM pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with chan | Jul 6, 2026 | 5.9 | 31 | NO | NO |
CVE-2026-42423HIGH OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that bypasses strictInlineEval explicit-approval requirements on gateway and node exec hosts. Attackers can | Apr 28, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-22034CRITICAL Snuffleupagus is a module that raises the cost of attacks against website by killing bug classes and providing a virtual patching system. On deployments of Snuffleupagus prior to v | Jan 8, 2026 | 9.8 | 30 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.