Common Weakness Enumeration
CWE Definition / CWE-636
CWE-636: Not Failing Securely ('Failing Open')
When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.
Published:18 Jan 2008
Organization:MITRE
Modified:11 Dec 2025
