CWE-696Class

Incorrect Behavior Order

Incomplete in the CWE catalog · 40 CVEs mapped

40
CVEs mapped
6.1
Median CVSS
What it is

The product performs multiple related behaviors, but the behaviors are performed in the wrong order in ways that may produce resultant weaknesses.

Recent examples
3.1cvss
CVE-2026-59305

CVE-2026-59305 - LOW Severity Vulnerability

Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6

LOWno explanation yet
0%
epss
6.5cvss
CVE-2026-68930

CVE-2026-68930 - MEDIUM Severity Vulnerability

Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, and the exec_request callback. Version 0.62.5 fixes the issue.

MEDIUMno explanation yet
0%
epss
9.3cvss
CVE-2026-44108

Firewall bypass during shutdown

Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise.

CRITICALno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-696
Abstraction
Class
Structure
Simple
Status
Incomplete