VYPR

CWE-636

Not Failing Securely ('Failing Open')

ClassDraft

Description

When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.

By entering a less secure state, the product inherits the weaknesses associated with that state, making it easier to compromise. At the least, it causes administrators to have a false sense of security. This weakness typically occurs as a result of wanting to "fail functional" to minimize administration and support costs, instead of "failing safe."

Hierarchy (View 1000)

Children

CVEs mapped to this weakness (58)

page 1 of 3
  • CVE-2024-43532HigOct 8, 2024
    risk 0.58cvss 8.8epss 0.12

    Remote Registry Service Elevation of Privilege Vulnerability

  • CVE-2026-68746HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.01

    Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to obtain full access to a Livebook server that enforces identity through Livebook Teams. A Livebook Agent or App Server connected to Livebook Teams caches the…

  • CVE-2026-53913CriJul 6, 2026
    risk 0.57cvss 9.8epss 0.01

    Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component. The KeycloakSecurityPolicy of camel-keycloak guards a route by running KeycloakSecurityProcessor.beforeProcess(), which…

  • CVE-2024-3729CriMay 2, 2024
    risk 0.57cvss 9.8epss 0.01

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'fea_encrypt' function in all versions up to, and including, 3.19.4. This makes it possible for unauthenticated attackers to manipulate the user…

  • CVE-2021-1578HigAug 25, 2021
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected device.…

  • CVE-2023-4030HigAug 17, 2023
    risk 0.55cvss 8.4epss 0.00

    A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to insecure settings if the BIOS becomes corrupt.

  • CVE-2026-53459CriSep 15, 2026
    risk 0.53cvss —epss 0.01

    Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and prior to version 0.2.4.4, a fail-open in the authentication code allows any attacker to bypass authentication by flooding a public endpoint to exhaust resources…

  • CVE-2026-81379HigSep 8, 2026
    risk 0.53cvss 8.2epss 0.01

    Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-18329HigSep 2, 2026
    risk 0.53cvss 8.2epss 0.00

    Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An…

  • CVE-2026-69306HigAug 11, 2026
    risk 0.53cvss 8.2epss 0.01

    Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-50528HigJul 14, 2026
    risk 0.53cvss 8.2epss 0.01

    Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-77866CriSep 15, 2026
    risk 0.52cvss —epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reach internal network destinations the library is configured to block. Only IPv4 addresses are matched against the reserved ranges and the blocklist. Every other…

  • CVE-2026-73421CriAug 13, 2026
    risk 0.52cvss —epss 0.01

    NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned by the auth() wrapper can fail open when Auth.js has a server configuration error. In…

  • CVE-2026-40525CriApr 17, 2026
    risk 0.52cvss 9.1epss 0.01

    OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authentication check fails open when the api_key configuration value is unset or empty. Remote attackers with network access to the exposed…

  • CVE-2025-54870HigAug 5, 2025
    risk 0.50cvss —epss 0.00

    VTun-ng is a Virtual Tunnel over TCP/IP network. In versions 3.0.17 and below, failure to initialize encryption modules might cause reversion to plaintext due to insufficient error handling. The bug was first introduced in VTun-ng version 3.0.12. This is fixed in version 3.0.18.…

  • CVE-2026-54762HigJun 23, 2026
    risk 0.49cvss 8.6epss 0.00

    Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerability in Traefik's Kubernetes Ingress NGINX provider that causes affected routes to fail open. When an Ingress explicitly enables BasicAuth or DigestAuth through…

  • CVE-2026-77560HigSep 21, 2026
    risk 0.46cvss 8.1epss 0.01

    Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to bypass per-app access controls with…

  • CVE-2026-85649HigSep 4, 2026
    risk 0.44cvss 7.9epss 0.00

    (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh. The installer invokes mkpasswd to generate yescrypt password hashes but does not…

  • CVE-2026-35205HigApr 9, 2026
    risk 0.44cvss 7.8epss 0.00

    Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.

  • CVE-2023-28842MedApr 4, 2023
    risk 0.44cvss 6.8epss 0.01

    Moby) is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as moby/moby is commonly referred to as…