The product performs multiple related behaviors, but the behaviors are performed in the wrong order in ways that may produce resultant weaknesses.
Volume of CVEs assigned to CWE-696 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35652CRITICAL OpenClaw before 2026.3.22 contains an authorization bypass vulnerability in interactive callback dispatch that allows non-allowlisted senders to execute action handlers. Attackers | Apr 10, 2026 | 9.1 | 34 | NO | NO |
CVE-2026-35640HIGH OpenClaw before 2026.3.25 parses JSON request bodies before validating webhook signatures, allowing unauthenticated attackers to force resource-intensive parsing operations. Remote | Apr 9, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-35386HIGH In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is | Apr 2, 2026 | 8.1 | 31 | NO | NO |
CVE-2026-45033HIGH GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulnerability has been identified in GitHub Copilot CLI where a m | May 13, 2026 | 7.8 | 30 | NO | NO |
CVE-2026-41254HIGH Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication. | Apr 18, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-40583HIGH UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction that passes signature, nonce, and balance pre | Apr 21, 2026 | 8.2 | 28 | NO | NO |
CVE-2026-44919MEDIUM In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. | May 14, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-35627HIGH OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages before enforcing sender and pairing policy validation. Attackers can trigg | Apr 9, 2026 | 8.2 | 27 | NO | NO |
CVE-2026-35637HIGH OpenClaw before 2026.3.22 performs cite expansion before completing channel and DM authorization checks, allowing cite work and content handling prior to final auth decisions. Atta | Apr 9, 2026 | 7.3 | 26 | NO | NO |
CVE-2026-43002MEDIUM An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be ex | May 5, 2026 | 5.3 | 24 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.