CWE-696— Incorrect Behavior Order
The product performs multiple related behaviors, but the behaviors are performed in the wrong order in ways that may produce resultant weaknesses.— MITRE CWE catalog
48 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-696page 1 of 1
- CVE-2026-44108CRITICALCVSS 9.8EG 9.82026-07-30
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowi…
- CVE-2026-40583HIGHCVSS 8.2EG 8.22026-04-21
UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction that passes signature, nonce, and balance prechecks, but fails authorization only after state mutation h…
- CVE-2026-14169HIGHCVSS 8.1EG 8.12026-07-28
Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device.
- CVE-2026-35386HIGHCVSS 8.1EG 8.12026-04-02
In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations …
- CVE-2026-105745HIGHCVSS 7.8EG 7.82026-10-05
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.27.0 until 2.131.0, Docling plugin factories in docling/models/factories/base_factory.py call load_setupt…
- CVE-2026-45033HIGHCVSS 7.8EG 7.82026-05-13
GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulnerability has been identified in GitHub Copilot CLI where a malicious bare git repository nested inside a project direct…
- CVE-2025-31485HIGHCVSS 7.5EG 7.52025-04-03
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Prior to 4.0.22 and 3.4.17, a GraphQL grant on a property might be cached with different objects. The ApiPlatform\GraphQl\Serializer\ItemNormalizer::isCacheKe…
- CVE-2021-22569HIGHCVSS 7.5EG 7.52022-01-10
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numb…
- CVE-2021-31379HIGHCVSS 7.5EG 7.52021-10-19
An Incorrect Behavior Order vulnerability in the MAP-E automatic tunneling mechanism of Juniper Networks Junos OS allows an attacker to send certain malformed IPv4 or IPv6 packets to cause a Denial of Service (DoS) to the PFE on the device…
- CVE-2026-73446HIGHCVSS 7.4EG 7.42026-09-15
On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency…
- CVE-2026-35637HIGHCVSS 7.3EG 7.32026-04-09
OpenClaw before 2026.3.22 performs cite expansion before completing channel and DM authorization checks, allowing cite work and content handling prior to final auth decisions. Attackers can exploit this timing vulnerability to access or ma…
- CVE-2024-24853HIGHCVSS 7.2EG 7.22024-08-14
Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2023-33224HIGHCVSS 7.2EG 7.22023-07-26
The SolarWinds Platform was susceptible to the Incorrect Behavior Order Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.
- CVE-2026-26287HIGHCVSS 7.1EG 7.12026-10-06
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.10.0 and prior to version 1.3.2, a bug in the `webhook` generator initialization order…
- CVE-2025-0150HIGHCVSS 7.1EG 7.12025-03-11
Incorrect behavior order in some Zoom Workplace Apps for iOS before version 6.3.0 may allow an authenticated user to conduct a denial of service via network access.
- CVE-2026-68930MEDIUMCVSS 6.5EG 6.52026-08-03
Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, and …
- CVE-2026-44919MEDIUMCVSS 6.5EG 6.52026-05-14
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.
- CVE-2026-35652MEDIUMCVSS 6.5EG 6.52026-04-10
OpenClaw before 2026.3.22 contains an authorization bypass vulnerability in interactive callback dispatch that allows non-allowlisted senders to execute action handlers. Attackers can bypass sender authorization checks by dispatching callb…
- CVE-2026-35636MEDIUMCVSS 6.5EG 6.52026-04-09
OpenClaw versions 2026.3.11 through 2026.3.24 contain a session isolation bypass vulnerability where session_status resolves sessionId to canonical session keys before enforcing visibility checks. Sandboxed child sessions can exploit this …
- CVE-2026-35627MEDIUMCVSS 6.5EG 6.52026-04-09
OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages before enforcing sender and pairing policy validation. Attackers can trigger unauthorized pre-authentication computation by sending c…
- CVE-2024-30389MEDIUMCVSS 5.8EG 5.82024-04-12
An Incorrect Behavior Order vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows an unauthenticated, network-based attacker to cause an integrity impact to networks downstream of the vuln…
- CVE-2024-30410MEDIUMCVSS 5.8EG 5.82024-04-12
An Incorrect Behavior Order in the routing engine (RE) of Juniper Networks Junos OS on EX4300 Series allows traffic intended to the device to reach the RE instead of being discarded when the discard term is set in loopback (lo0) interfac…
- CVE-2021-47688MEDIUMCVSS 5.7EG 5.72025-06-23
In WhiteBeam 0.2.0 through 0.2.1 before 0.2.2, a user with local access to a server can bypass the allow-list functionality because a file can be truncated in the OpenFileDescriptor action before the VerifyCanWrite action is performed.
- CVE-2026-33305MEDIUMCVSS 5.4EG 5.42026-03-19
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in the optional FaxSMS module (`oe-module-faxsms`) allows any authenticated OpenEMR user to …
- CVE-2026-103353MEDIUMCVSS 5.3EG 5.32026-10-01
Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14.
- CVE-2026-67217MEDIUMCVSS 5.3EG 5.32026-07-29
cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the exis…
- CVE-2026-43002MEDIUMCVSS 5.3EG 5.32026-05-05
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression o…
- CVE-2026-35640MEDIUMCVSS 5.3EG 5.32026-04-09
OpenClaw before 2026.3.25 parses JSON request bodies before validating webhook signatures, allowing unauthenticated attackers to force resource-intensive parsing operations. Remote attackers can send malicious webhook requests to trigger d…
- CVE-2025-9904MEDIUMCVSS 5.3EG 5.32025-09-29
Unallocated memory access vulnerability in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer Driver / Generic Plus LIPSLX Printer Driver / Generic Plus PS Printer Driver …
- CVE-2025-55114MEDIUMCVSS 5.3EG 5.32025-09-16
The improper order of AUTHORIZED_CTM_IP validation in the Control-M/Agent, where the Control-M/Server IP address is validated only after the SSL/TLS handshake is completed, exposes the Control-M/Agent to vulnerabilities in the SSL/TLS impl…
- CVE-2024-35229MEDIUMCVSS 5.3EG 5.32024-05-27
ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. Prior to version 1.3.10, there is a very specific pattern `f(a(),b()); check_if_a_executed_last()` in Yul that exposes a bug in evaluation order of Yul funct…
- CVE-2023-44386MEDIUMCVSS 5.3EG 5.32023-10-05
Vapor is an HTTP web framework for Swift. There is a denial of service vulnerability impacting all users of affected versions of Vapor. The HTTP1 error handler closed connections when HTTP parse errors occur instead of passing them on. The…
- CVE-2024-45157MEDIUMCVSS 5.1EG 5.12024-09-05
An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRB…
- CVE-2025-20012MEDIUMCVSS 4.9EG 4.92025-05-13
Incorrect behavior order for some Intel(R) Core™ Ultra Processors may allow an unauthenticated user to potentially enable information disclosure via physical access.
- CVE-2023-52968MEDIUMCVSS 4.9EG 4.92025-03-08
MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11.0.5, and 11.1 before 11.1.4 calls fix_fields_if_needed under mysql_derived_prepare when derived is not yet prep…
- CVE-2026-65100MEDIUMCVSS 4.8EG 4.82026-07-29
Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the co…
- CVE-2026-40223MEDIUMCVSS 4.7EG 4.72026-04-10
In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.
- CVE-2026-93330MEDIUMCVSS 4.3EG 4.32026-09-29
Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway host ruleset.
- CVE-2023-23576MEDIUMCVSS 4.3EG 4.32023-12-18
Incorrect behavior order in the Command Centre Server could allow privileged users to gain physical access to the site for longer than intended after a network outage when competencies are used in the access decision. This issue affects…
- CVE-2026-41254MEDIUMCVSS 4.0EG 4.02026-04-18
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
- CVE-2025-48965MEDIUMCVSS 4.0EG 4.02025-07-20
Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL but val.len greater than zero.
- CVE-2026-59305LOWCVSS 3.8EG 3.82026-08-27
Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6
- CVE-2026-93304LOWCVSS 3.7EG 3.72026-09-27
A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at that point, so the client installs read keys derived from a known (deterministic) key and checks the s…
- CVE-2026-56355LOWCVSS 3.7EG 3.72026-06-20
GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
- CVE-2026-44600LOWCVSS 3.7EG 3.72026-05-07
Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-2026-010.
- CVE-2026-49318LOWCVSS 2.4EG 2.42026-05-29
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireles…
- CVE-2026-49317LOWCVSS 2.4EG 2.42026-05-29
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireles…
- CVE-2026-103012LOWCVSS 2.0EG 2.02026-09-30
Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead of the user's valid Claude Enterprise or Team sign-in when fetching the organization's server-manag…
Map vulnerabilities like CWE-696 to your infrastructure
EchelonGraph correlates every CVE — across CWE-696 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →