Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-636

Not Failing Securely ('Failing Open')

When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.

40
Assigned CVEs
250th
Commonality Rank
6.7
Avg CVSS
0.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-636 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 16, 2021
5 years ago
Most Recent CVE
Jul 17, 2026
6 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-53913CRITICAL
Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component. The KeycloakSecurity
Jul 6, 20269.843NONO
CVE-2026-50528HIGH
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
Jul 14, 20268.236NONO
CVE-2026-53712HIGH
SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication mechanisms. Prior to 3.
Jul 17, 20268.235NONO
CVE-2026-54762HIGH
Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerability in Traefik's Kubernetes Ingress NGINX provider that causes
Jun 23, 20268.635NONO
CVE-2024-43532HIGH
Remote Registry Service Elevation of Privilege Vulnerability
Oct 8, 20248.834NONO
CVE-2026-42246HIGH
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cau
May 9, 20267.433NONO
CVE-2026-40525CRITICAL
OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authentication check fails open when the api
Apr 17, 20269.133NONO
CVE-2026-54291MEDIUM
pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with chan
Jul 6, 20265.931NONO
CVE-2026-42423HIGH
OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that bypasses strictInlineEval explicit-approval requirements on gateway and node exec hosts. Attackers can
Apr 28, 20267.530NONO
CVE-2026-22034CRITICAL
Snuffleupagus is a module that raises the cost of attacks against website by killing bug classes and providing a virtual patching system. On deployments of Snuffleupagus prior to v
Jan 8, 20269.830NONO
View all 40 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
10%
4.0-4.9
18%
19%
5.0-5.9
15%
16%
6.0-6.9
20%
26%
7.0-7.9
18%
11%
8.0-8.9
10%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products