CWE-321— Use of Hard-coded Cryptographic Key
The product uses a hard-coded, unchangeable cryptographic key.— MITRE CWE catalog
361 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-321page 8 of 8
- CVE-2026-8243MEDIUMCVSS 5.3EG 5.32026-05-10
A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03. This affects an unknown function of the component JNLP Deployment Endpoint. Executing a manipulation can lead to use of hard-coded cryptographic key . …
- CVE-2026-84483MEDIUMCVSS 5.3EG 5.32026-09-01
WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens using the public site URL and current time. Attackers can forge aut…
- CVE-2026-86241MEDIUMCVSS 4.3EG 4.32026-09-07
A weakness has been identified in liufee FeehiCMS up to 2.1.1. This impacts an unknown function of the file environments/prod/backend/config/main-local.php of the component Cookie Validation. This manipulation of the argument cookieValidat…
- CVE-2026-8739MEDIUMCVSS 5.3EG 5.32026-05-17
A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the file publiccms-core/src/main/java/com/publiccms/logic/component/config/SafeConfigComponent.java. The manipulation of the a…
- CVE-2026-87929CRITICALCVSS 9.8EG 9.82026-09-09
MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mi…
- CVE-2026-89026CRITICALCVSS 9.8EG 9.82026-09-15
The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated …
- CVE-2026-90510HIGHCVSS 8.3EG 8.32026-09-13
A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/…
- CVE-2026-90945CRITICALCVSS 9.8EG 9.82026-09-14
Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative …
- CVE-2026-9220HIGHCVSS 7.5EG 7.52026-06-26
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initialization vectors. This allows an attacker to decrypt Setracker2 wat…
- CVE-2026-9260CRITICALCVSS 9.8EG 9.82026-06-16
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
- CVE-2026-9770MEDIUMCVSS 5.3EG 5.32026-07-15
Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices. An attacker with access to the firmware image can extract the embedded key. Success…
Map vulnerabilities like CWE-321 to your infrastructure
EchelonGraph correlates every CVE — across CWE-321 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →