CWE-1392— Use of Default Credentials
The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.— MITRE CWE catalog
116 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1392page 3 of 3
- CVE-2026-46386CRITICALCVSS 9.9EG 9.92026-06-26
OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :mar…
- CVE-2026-50005HIGHCVSS 7.7EG 7.72026-06-11
Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds.
- CVE-2026-58453CRITICALCVSS 9.8EG 9.82026-07-01
JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to gain unauthorized access by using the default admin username with an empty passwo…
- CVE-2026-58466CRITICALCVSS 9.8EG 9.82026-07-02
AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly known default credentials seeded at startup via add_default_u…
- CVE-2026-65313HIGHCVSS 8.1EG 8.12026-07-31
A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker wit…
- CVE-2026-68503CRITICALCVSS 9.8EG 9.82026-07-30
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.…
- CVE-2026-7365HIGHCVSS 7.8EG 8.42026-05-27
IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass …
- CVE-2026-7428CRITICALCVSS 9.2EG 9.22026-05-12
Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could have been exploited by a remote attacker to gain full…
- CVE-2026-76155CRITICALCVSS 9.3EG 9.32026-08-21
Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default administrator credentials.
- CVE-2026-78573CRITICALCVSS 9.8EG 9.82026-09-10
IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.
- CVE-2026-86464CRITICALCVSS 9.9EG 9.92026-09-08
In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. …
- CVE-2026-90451HIGHCVSS 8.2EG 8.22026-09-11
An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration wit…
- CVE-2026-90456CRITICALCVSS 9.2EG 9.22026-09-11
An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the set…
- CVE-2026-90498HIGHCVSS 7.3EG 7.32026-09-13
A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. Remote exploitation of the attack is possible. The ex…
- CVE-2026-90940MEDIUMCVSS 5.3EG 5.32026-09-14
novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL pa…
- CVE-2026-9844HIGHCVSS 8.8EG 8.82026-06-02
Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Passwords. This issue affects navify Digital Pathology: from 2.0.0 before 2.4.1.
Map vulnerabilities like CWE-1392 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1392 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →