What is CWE-1188?
The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.
CWE-1188 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.
Source: MITRE CWE (CWE-1188 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Other — Varies by Context. The impact of insecure defaults varies widely depending on the functionality that the product controls.
Source: MITRE CWE, common consequences.
How CWE-1188 is exploited in the wild
Threadlinqs maps 7 CVEs to CWE-1188, published between 2023-12-05 and 2026-10-01. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 2 critical, 3 high, 1 medium. The highest EPSS score in the set is 13.2% (CVE-2023-6448), the modelled probability of exploitation in the next 30 days. 41 tracked threats reference CWE-1188 directly or through a CVE it covers; the most recent is “AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal Credentials - CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, CVE-2026-104019” (2026-10-03). Affected products concentrate in Johnson Controls (1), MervinPraison (1), Microsoft (1), among 6 vendors in total.
Vulnerabilities (CVEs)
All 7 CVEs mapped to CWE-1188, CISA KEV first, then by CVSS score.
- CVE-2023-6448 — CISA KEV · CVSS 9.8 critical · EPSS 13.2% · published 2023-12-05
- CVE-2026-41679 — CVSS 10 critical · EPSS 2.9% · published 2026-04-23
- CVE-2024-32114 — CVSS 8.5 high · EPSS 2.0% · published 2024-05-02
- CVE-2026-77348 — CVSS 8.2 high · EPSS 0.2% · published 2026-08-31
- CVE-2026-44338 — CVSS 7.3 high · EPSS 0.0% · published 2026-05-08
- CVE-2026-26122 — CVSS 6.5 medium · EPSS 0.5% · published 2026-03-05
- CVE-2026-71448 — EPSS 0.1% · published 2026-10-01
Affected vendors
- Johnson Controls — 1 CVE
- MervinPraison — 1 CVE
- Microsoft — 1 CVE
- Unitronics — 1 CVE
- ellite — 1 CVE
- paperclipai — 1 CVE
Threat activity
41 tracked threats cite CWE-1188; the 25 most recent are listed.
- AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal Credentials - CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, CVE-2026-104019CRITICAL
- Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent ImportsCRITICAL
- CVE-2026-66066 "KindaRails2Shell": Critical Ruby on Rails Active Storage Flaw Allows Unauthenticated Arbitrary File Read / RCE via libvips Image ProcessingCRITICAL
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to Cavern Manticore/Lyceum (Low Confidence)HIGH
- CVE-2026-52824: Kimai Docker Image Hardcoded APP_SECRET Enables Account TakeoverHIGH
- CodeTracer: Forensic Attribution Tool for Backdoored AI Code-Completion ModelsLOW
- xAI Grok Build CLI 0-Day: Trust-Boundary Bypass Chains Enable Arbitrary Code Execution via AGENTS.md/CLAUDE.md Prompt Injection (also affects Claude Code CLI)HIGH
- Backdoor.Stupig — Windows Login-Screen Keyboard-Layout Provider Backdoor Grants SYSTEM Access, Deployed Alongside Resurfaced DaxinHIGH
- SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command Injection (CVE-2026-15410, CVSS 7.2) Under Active Zero-Day ExploitationCRITICAL
- Cursor AI Code Editor Autorun Flaw Enables Silent Code Execution via Malicious RepositoriesHIGH
- Misconfigured Server Exposes Three Evilginx-Based Microsoft 365 Phishing Operations (codemado, mail-argenta, saroula01)HIGH
- NetNut Residential Proxy Botnet (aka Popa) Disrupted by Google and FBI — 2 Million Devices Used for Password-Spraying and C2 MaskingHIGH
- Multi-Malware Campaign Targeting Poorly Secured Linux SSH Servers — XMRig, ShellBot, MIG LogCleaner, XHide, and Go-based Propagation ToolMEDIUM
- FortiBleed Credential-Harvesting Campaign Feeds INC Ransom and Lynx Ransomware-as-a-Service OperationsCRITICAL
- FBI Seizes NetNut Residential Proxy Platform Tied to Popa Botnet (2M+ Devices) — Alarum Technologies, Kimwolf/Vo1d ConvergenceHIGH
- FortiBleed Credential-Theft Campaign Linked to INC and Lynx Ransomware OperationsCRITICAL
- Amadey: Commodity Loader/Botnet Evolved into RAT — Dominant LockBit 3.0 Loader, Adopted by FSB's Secret Blizzard Against Ukrainian MilitaryHIGH
- Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares[.]com / wetransfer[.]ICU SEO-Poisoning Operation)HIGH
- Exposed RDP / RDWeb Misconfigurations Exploited for Initial Access and Lateral Movement (Huntress 2026)HIGH
- Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and Fakeset Backdoors Against U.S. Bank, Airport, and Defense Software CompanyCRITICAL
- Capita Black Basta Ransomware Incident (March 2023) — Record £14M UK ICO Fine for 6M+ Affected IndividualsHIGH
- MyFlaw: Cross-Platform RCE in Opera and Opera GX Browsers via the Built-in 'Opera Touch Background' Extension (My Flow Feature)HIGH
- RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader and RemotePELoader Multi-Stage ChainHIGH
- NSO Group Pegasus Spyware — WhatsApp Spearphishing Campaign Alleged in Meta Contempt Complaint (June 2026)HIGH
- JINX-0164 — Crypto-Targeting macOS AUDIOFIX RAT via LinkedIn Social Engineering and Internal CI/CD Hijacking (Wiz CIRT)CRITICAL
Detection methods (MITRE CWE)
- Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.