# CWE-1188: Initialization of a Resource with an Insecure Default

**KEV-linked**

> As of 2026-10-05, CWE-1188 (Initialization of a Resource with an Insecure Default) underlies 7 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 41 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-1188?

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

CWE-1188 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/1188.html) (CWE-1188 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Other** — Varies by Context. The impact of insecure defaults varies widely depending on the functionality that the product controls.

_Source: MITRE CWE, common consequences._

## How CWE-1188 is exploited in the wild

Threadlinqs maps 7 CVEs to CWE-1188, published between 2023-12-05 and 2026-10-01. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 2 critical, 3 high, 1 medium. The highest EPSS score in the set is 13.2% (CVE-2023-6448), the modelled probability of exploitation in the next 30 days. 41 tracked threats reference CWE-1188 directly or through a CVE it covers; the most recent is “AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal Credentials - CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, CVE-2026-104019” (2026-10-03). Affected products concentrate in Johnson Controls (1), MervinPraison (1), Microsoft (1), among 6 vendors in total.

## Vulnerabilities (CVEs)

All 7 CVEs mapped to CWE-1188, CISA KEV first, then by CVSS score.

- [CVE-2023-6448](https://intel.threadlinqs.com/cve/CVE-2023-6448) — CISA KEV · CVSS 9.8 critical · EPSS 13.2% · published 2023-12-05
- [CVE-2026-41679](https://intel.threadlinqs.com/cve/CVE-2026-41679) — CVSS 10 critical · EPSS 2.9% · published 2026-04-23
- [CVE-2024-32114](https://intel.threadlinqs.com/cve/CVE-2024-32114) — CVSS 8.5 high · EPSS 2.0% · published 2024-05-02
- [CVE-2026-77348](https://intel.threadlinqs.com/cve/CVE-2026-77348) — CVSS 8.2 high · EPSS 0.2% · published 2026-08-31
- [CVE-2026-44338](https://intel.threadlinqs.com/cve/CVE-2026-44338) — CVSS 7.3 high · EPSS 0.0% · published 2026-05-08
- [CVE-2026-26122](https://intel.threadlinqs.com/cve/CVE-2026-26122) — CVSS 6.5 medium · EPSS 0.5% · published 2026-03-05
- [CVE-2026-71448](https://intel.threadlinqs.com/cve/CVE-2026-71448) — EPSS 0.1% · published 2026-10-01

## Affected vendors

- [Johnson Controls](https://intel.threadlinqs.com/vendors/johnson-controls) — 1 CVE
- [MervinPraison](https://intel.threadlinqs.com/vendors/mervinpraison) — 1 CVE
- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 1 CVE
- **Unitronics** — 1 CVE
- **ellite** — 1 CVE
- **paperclipai** — 1 CVE

## Threat activity

41 tracked threats cite CWE-1188; the 25 most recent are listed.

- [AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal Credentials - CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, CVE-2026-104019](https://intel.threadlinqs.com/threat/TL-2026-2860) — CRITICAL · 2026-10-03
- [Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports](https://intel.threadlinqs.com/threat/TL-2026-1892) — CRITICAL · 2026-08-05
- [CVE-2026-66066 "KindaRails2Shell": Critical Ruby on Rails Active Storage Flaw Allows Unauthenticated Arbitrary File Read / RCE via libvips Image Processing](https://intel.threadlinqs.com/threat/TL-2026-1755) — CRITICAL · 2026-07-29
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to Cavern Manticore/Lyceum (Low Confidence)](https://intel.threadlinqs.com/threat/TL-2026-1553) — HIGH · 2026-07-20
- [CVE-2026-52824: Kimai Docker Image Hardcoded APP_SECRET Enables Account Takeover](https://intel.threadlinqs.com/threat/TL-2026-1556) — HIGH · 2026-07-20
- [CodeTracer: Forensic Attribution Tool for Backdoored AI Code-Completion Models](https://intel.threadlinqs.com/threat/TL-2026-1577) — LOW · 2026-07-20
- [xAI Grok Build CLI 0-Day: Trust-Boundary Bypass Chains Enable Arbitrary Code Execution via AGENTS.md/CLAUDE.md Prompt Injection (also affects Claude Code CLI)](https://intel.threadlinqs.com/threat/TL-2026-1472) — HIGH · 2026-07-18
- [Backdoor.Stupig — Windows Login-Screen Keyboard-Layout Provider Backdoor Grants SYSTEM Access, Deployed Alongside Resurfaced Daxin](https://intel.threadlinqs.com/threat/TL-2026-1400) — HIGH · 2026-07-16
- [SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command Injection (CVE-2026-15410, CVSS 7.2) Under Active Zero-Day Exploitation](https://intel.threadlinqs.com/threat/TL-2026-1390) — CRITICAL · 2026-07-15
- [Cursor AI Code Editor Autorun Flaw Enables Silent Code Execution via Malicious Repositories](https://intel.threadlinqs.com/threat/TL-2026-1307) — HIGH · 2026-07-14
- [Misconfigured Server Exposes Three Evilginx-Based Microsoft 365 Phishing Operations (codemado, mail-argenta, saroula01)](https://intel.threadlinqs.com/threat/TL-2026-1258) — HIGH · 2026-07-13
- [NetNut Residential Proxy Botnet (aka Popa) Disrupted by Google and FBI — 2 Million Devices Used for Password-Spraying and C2 Masking](https://intel.threadlinqs.com/threat/TL-2026-1112) — HIGH · 2026-07-03
- [Multi-Malware Campaign Targeting Poorly Secured Linux SSH Servers — XMRig, ShellBot, MIG LogCleaner, XHide, and Go-based Propagation Tool](https://intel.threadlinqs.com/threat/TL-2026-1156) — MEDIUM · 2026-07-03
- [FortiBleed Credential-Harvesting Campaign Feeds INC Ransom and Lynx Ransomware-as-a-Service Operations](https://intel.threadlinqs.com/threat/TL-2026-1056) — CRITICAL · 2026-07-02
- [FBI Seizes NetNut Residential Proxy Platform Tied to Popa Botnet (2M+ Devices) — Alarum Technologies, Kimwolf/Vo1d Convergence](https://intel.threadlinqs.com/threat/TL-2026-1084) — HIGH · 2026-07-02
- [FortiBleed Credential-Theft Campaign Linked to INC and Lynx Ransomware Operations](https://intel.threadlinqs.com/threat/TL-2026-1085) — CRITICAL · 2026-07-02
- [Amadey: Commodity Loader/Botnet Evolved into RAT — Dominant LockBit 3.0 Loader, Adopted by FSB's Secret Blizzard Against Ukrainian Military](https://intel.threadlinqs.com/threat/TL-2026-1029) — HIGH · 2026-07-01
- [Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares\[.\]com / wetransfer\[.\]ICU SEO-Poisoning Operation)](https://intel.threadlinqs.com/threat/TL-2026-0799) — HIGH · 2026-06-15
- [Exposed RDP / RDWeb Misconfigurations Exploited for Initial Access and Lateral Movement (Huntress 2026)](https://intel.threadlinqs.com/threat/TL-2026-0775) — HIGH · 2026-06-11
- [Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and Fakeset Backdoors Against U.S. Bank, Airport, and Defense Software Company](https://intel.threadlinqs.com/threat/TL-2026-0757) — CRITICAL · 2026-06-10
- [Capita Black Basta Ransomware Incident (March 2023) — Record £14M UK ICO Fine for 6M+ Affected Individuals](https://intel.threadlinqs.com/threat/TL-2026-0767) — HIGH · 2026-06-10
- [MyFlaw: Cross-Platform RCE in Opera and Opera GX Browsers via the Built-in 'Opera Touch Background' Extension (My Flow Feature)](https://intel.threadlinqs.com/threat/TL-2026-0770) — HIGH · 2026-06-10
- [RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader and RemotePELoader Multi-Stage Chain](https://intel.threadlinqs.com/threat/TL-2026-0722) — HIGH · 2026-06-09
- [NSO Group Pegasus Spyware — WhatsApp Spearphishing Campaign Alleged in Meta Contempt Complaint (June 2026)](https://intel.threadlinqs.com/threat/TL-2026-0728) — HIGH · 2026-06-09
- [JINX-0164 — Crypto-Targeting macOS AUDIOFIX RAT via LinkedIn Social Engineering and Internal CI/CD Hijacking (Wiz CIRT)](https://intel.threadlinqs.com/threat/TL-2026-0607) — CRITICAL · 2026-05-27

## Detection methods (MITRE CWE)

- **Automated Static Analysis**: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-1419](https://cwe.mitre.org/data/definitions/1419.html)
- [CWE-344](https://cwe.mitre.org/data/definitions/344.html)
- CWE-665 Improper Initialization

Canonical: https://intel.threadlinqs.com/cwe/CWE-1188
Source definition: https://cwe.mitre.org/data/definitions/1188.html
Detection rules and IOCs for threats exploiting CWE-1188 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
