Insecure Default Initialization (CWE-1188)
CWE-1188 covers products that ship a resource with a default value meant to be changed by the installer, administrator or maintainer, where that default is not secure. Developers often pick defaults that keep a product open and easy to use out of the box, and the weakness appears when the default is left in place. MITRE lists insecure default variable initialization (CWE-453) as a child and places the entry under Incorrect Initialization of Resource (CWE-1419).
About CWE-1188
MITRE rates the impact as varying by context, because the damage depends on what the insecure default controls. Its observed examples include a database browser whose default mode exposes a web server to the network and a firmware variable default that allows denial of service.
Mitigations
- +Ship a secure configuration as the default baseline, so the product resists common attacks without extra setup.
- +Do not ship universally shared default passwords; require a strong password during installation or set a unique password per device.
- +Make multifactor authentication for privileged users opt-out rather than opt-in.
- +Move hardening guide settings into the default configuration and document risky changes in a loosening guide instead.
- +Use threat modeling to decide which features and protocols are enabled by default.
Detection
MITRE lists automated static analysis (SAST), which can find some instances by tracing data flow from input sources to sinks.
CWE-1188 Vulnerabilities
5 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2025-48927 | TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability | TeleMessage | 5.3 | 11.1% | KEV | 2025-05-28 |
| CVE-2023-27524 | Apache Superset: Session validation vulnerability when using provided default SECRET_KEY | Apache Software Foundation | 8.9 | 97.4% | KEV | 2023-04-24 |
| CVE-2023-6448 | Unitronics VisiLogic uses a default administrative password | Unitronics | 9.8 | 2.1% | KEV | 2023-12-05 |
| CVE-2022-24706 | Remote Code Execution Vulnerability in Packaging | Apache Software Foundation | 9.8 | 92.5% | KEV | 2022-04-26 |
| CVE-2026-66066 | Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing | rails | 9.5 | 27.9% | 2026-07-30 |
Most Affected Vendors
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-1188?→
CWE-1188 is the initialization of a resource with an insecure default: a setting the product expects an administrator to change ships in a state that is not secure. MITRE renamed it from Insecure Default Initialization of Resource in October 2023.
Is a default password an example of CWE-1188?→
A universally shared default password is an insecure default of this kind. CISA and partner agencies advise manufacturers to eliminate default passwords by requiring a strong password at setup or shipping a unique password for each device.
How many exploited vulnerabilities are classified as CWE-1188?→
This database lists 5 CVE records mapped to CWE-1188 by their CVE Numbering Authority. 4 of them are in the CISA Known Exploited Vulnerabilities catalog. Examples include CVE-2025-48927, CVE-2023-27524, CVE-2023-6448.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.