CWE-696: Incorrect Behavior Order
The product performs multiple related behaviors, but the behaviors are performed in the wrong order in ways that may produce resultant weaknesses.
Last updated
Overview
CWE-696 (Incorrect Behavior Order) is a class-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
38 recorded CVEs are caused by CWE-696 (Incorrect Behavior Order). The highest-severity and most recent are shown first. 21 new CWE-696 CVEs have been recorded so far in 2026 (8 in 2025).
- CVE-2026-44108
Firewall bypass during shutdown
Critical · CVSS 9.3 · EPSS 41th2026-07-30 - CVE-2026-40583
UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt
High · CVSS 8.8 · EPSS 31th2026-04-21 - CVE-2026-35627
OpenClaw < 2026.3.22 - Unauthenticated Cryptographic Work in Nostr Inbound DM Handling
High · CVSS 8.6 · EPSS 38th2026-04-09