Threadlinqs IntelligenceStart free

Weakness · BaseCWE-1188

CWE-1188: Initialization of a Resource with an Insecure Default

KEV-linkedBase

As of 2026-10-05, CWE-1188 (Initialization of a Resource with an Insecure Default) underlies 7 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 41 tracked threats.

CVEs
7Mapped to CWE-1188
CISA KEV
1Exploited in the wild
Critical
2CVSS v3 critical CVEs
Threats
41Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-1188?

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

CWE-1188 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.

Source: MITRE CWE (CWE-1188 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Other — Varies by Context. The impact of insecure defaults varies widely depending on the functionality that the product controls.

Source: MITRE CWE, common consequences.

How CWE-1188 is exploited in the wild

Threadlinqs maps 7 CVEs to CWE-1188, published between 2023-12-05 and 2026-10-01. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 2 critical, 3 high, 1 medium. The highest EPSS score in the set is 13.2% (CVE-2023-6448), the modelled probability of exploitation in the next 30 days. 41 tracked threats reference CWE-1188 directly or through a CVE it covers; the most recent is “AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal Credentials - CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, CVE-2026-104019” (2026-10-03). Affected products concentrate in Johnson Controls (1), MervinPraison (1), Microsoft (1), among 6 vendors in total.

Vulnerabilities (CVEs)

All 7 CVEs mapped to CWE-1188, CISA KEV first, then by CVSS score.

  • CVE-2023-6448 — CISA KEV · CVSS 9.8 critical · EPSS 13.2% · published 2023-12-05
  • CVE-2026-41679 — CVSS 10 critical · EPSS 2.9% · published 2026-04-23
  • CVE-2024-32114 — CVSS 8.5 high · EPSS 2.0% · published 2024-05-02
  • CVE-2026-77348 — CVSS 8.2 high · EPSS 0.2% · published 2026-08-31
  • CVE-2026-44338 — CVSS 7.3 high · EPSS 0.0% · published 2026-05-08
  • CVE-2026-26122 — CVSS 6.5 medium · EPSS 0.5% · published 2026-03-05
  • CVE-2026-71448 — EPSS 0.1% · published 2026-10-01

Affected vendors

Threat activity

41 tracked threats cite CWE-1188; the 25 most recent are listed.

Detection methods (MITRE CWE)

  • Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.