What is security misconfiguration?

Updated May 6, 2026

Short answer

Security misconfiguration occurs when systems are improperly set up.

Deep explanation

Includes default credentials, open ports, verbose errors, and unnecessary services.

Real-world example

Exposed admin panels on servers.

Common mistakes

  • Leaving default configs unchanged.

Follow-up questions

  • How to detect misconfigurations?
  • What is hardening?

More Web Security interview questions

View all →