CWE-841— Improper Enforcement of Behavioral Workflow
The product supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.— MITRE CWE catalog
73 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-841page 2 of 2
- CVE-2026-34582CRITICALCVSS 9.1EG 9.12026-04-07
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentic…
- CVE-2026-41259HIGHCVSS 7.5EG 7.52026-04-23
Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Mastodon allows restricting new user sign-up based on e-mail domain names, and performs basic validation on e-mail addresses…
- CVE-2026-42246HIGHCVSS 7.4EG 7.42026-05-09
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without sta…
- CVE-2026-42303MEDIUMCVSS 6.1EG 6.12026-05-12
Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification and duplicate privacy request detection are affected by a vulnerability in which an admini…
- CVE-2026-43937HIGHCVSS 8.8EG 8.82026-05-12
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttribute rewrites the response to a 302 to /Info/4. The most impactful abuse is /Admin/RunSq…
- CVE-2026-43974HIGHCVSS 7.5EG 7.52026-06-08
Unexpected Status Code or Return Value vulnerability in ninenines gun (gun_http module) allows a malicious HTTP server to force the client into raw protocol mode via an unsolicited 101 Switching Protocols response. In gun_http:handle_info…
- CVE-2026-45023MEDIUMCVSS 5.4EG 5.42026-05-28
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.59, POST /api/blocks/{block_id}/execute endpoint executes blocks without consuming any credits, regardl…
- CVE-2026-46540MEDIUMCVSS 6.5EG 6.52026-06-10
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, when LightBlockchain::rebranch() adopts a fork chain whose tip is a macro block (checkpoint or election…
- CVE-2026-48505HIGHCVSS 7.4EG 7.42026-06-22
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, a flaw in the handling of recovery codes for app-based multi-factor authentication allows the same recovery code to b…
- CVE-2026-53637MEDIUMCVSS 6.5EG 6.52026-07-09
Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is comp…
- CVE-2026-55763HIGHCVSS 8.7EG 8.72026-08-28
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accounts/accounts.go calls SubFromBalance after the split loop and after the royaltiesToPay <= 0 early r…
- CVE-2026-57536MEDIUMCVSS 6.3EG 6.32026-06-25
Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to m…
- CVE-2026-67279MEDIUMCVSS 6.9EG 6.92026-09-05
RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the s…
- CVE-2026-75081MEDIUMCVSS 4.3EG 4.32026-08-17
A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enforcement of behaviora…
- CVE-2026-77508LOWCVSS 3.5EG 3.52026-08-26
Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{username}/ without verifying the new address, allowing a later team invita…
- CVE-2026-78103MEDIUMCVSS 5.1EG 5.12026-08-27
WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not enforce this lock/unlock workflow state, allowing an authenticated administrator to submit configura…
- CVE-2026-78135HIGHCVSS 7.3EG 7.32026-09-11
libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
- CVE-2026-78618MEDIUMCVSS 6.9EG 6.92026-08-27
A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially crafted request.
- CVE-2026-79083HIGHCVSS 7.5EG 7.52026-08-25
Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML pa…
- CVE-2026-80195MEDIUMCVSS 5.4EG 5.42026-08-25
Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members before validating the submitted replacement member list. …
- CVE-2026-82423MEDIUMCVSS 5.4EG 5.42026-08-29
A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId leads to enforcemen…
- CVE-2026-8477LOWCVSS 2.7EG 2.72026-05-26
Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server allows an authenticated user with access to a sealed entry to retrieve its sensitive data without triggering the unseal a…
- CVE-2026-87503MEDIUMCVSS 6.5EG 6.52026-09-09
Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severi…
Map vulnerabilities like CWE-841 to your infrastructure
EchelonGraph correlates every CVE — across CWE-841 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →