M8:2024: Security Misconfiguration
Insecure default permissions, exported components, backup settings, or backend configuration that widen the app's attack surface beyond what is necessary.
How it's found
Found by reviewing app permissions, exported components, and backend configuration for insecure defaults.
Standards mapping
How TurboPentest tests for this (white-box)
This weakness (Configuration) is caught by white-box static analysis when you connect a GitHub repo: IntegSec's Opengrep SAST rule pack carries 8 rules for it, flagging the issue directly in your source code as part of the pentest.
Frequently asked questions
What is M8:2024 Security Misconfiguration?
Insecure default permissions, exported components, backup settings, or backend configuration that widen the app's attack surface beyond what is necessary.
How do you find Security Misconfiguration?
Found by reviewing app permissions, exported components, and backend configuration for insecure defaults.
Which CWEs map to M8:2024?
M8:2024 maps to CWE-16, CWE-276.
Does TurboPentest test for Security Misconfiguration?
This weakness (Configuration) is caught by white-box static analysis when you connect a GitHub repo: IntegSec's Opengrep SAST rule pack carries 8 rules for it, flagging the issue directly in your source code as part of the pentest.
Related OWASP categories
- OWASP Mobile Top 10M1:2024: Improper Credential Usage
- OWASP Mobile Top 10M2:2024: Inadequate Supply Chain Security
- OWASP Mobile Top 10M3:2024: Insecure Authentication/Authorization
- OWASP Mobile Top 10M4:2024: Insufficient Input/Output Validation
- OWASP Mobile Top 10M5:2024: Insecure Communication
- OWASP Mobile Top 10M6:2024: Inadequate Privacy Controls
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest