CWE-522— Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.— MITRE CWE catalog
1,562 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-522page 30 of 32
- CVE-2026-20435MEDIUMCVSS 4.6EG 4.62026-03-02
In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. Us…
- CVE-2026-20733MEDIUMCVSS 5.3EG 6.52026-02-27
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-20791HIGHCVSS 7.5EG 7.52026-02-27
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-21660CRITICALCVSS 9.8EG 9.82026-02-27
Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and p…
- CVE-2026-21670HIGHCVSS 6.5EG 7.72026-03-12
A vulnerability allowing a low-privileged user to extract saved SSH credentials.
- CVE-2026-21852HIGHCVSS 7.5EG 7.52026-01-21
Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before users confirmed trust. An attacker-contr…
- CVE-2026-22043CRITICALCVSS 9.8EG 9.82026-01-08
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in RustFS IAM allows a restricted service account or STS credential to self-issue an unrestr…
- CVE-2026-22240HIGHCVSS 7.5EG 7.52026-01-14
The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP…
- CVE-2026-2255MEDIUMCVSS 4.3EG 4.32026-05-27
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those e…
- CVE-2026-22574MEDIUMCVSS 4.1EG 4.12026-04-14
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 thro…
- CVE-2026-22576MEDIUMCVSS 4.3EG 4.32026-04-14
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 thro…
- CVE-2026-22878MEDIUMCVSS 5.3EG 6.52026-02-27
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-22890MEDIUMCVSS 5.3EG 6.52026-02-27
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-22911MEDIUMCVSS 7.5EG 5.32026-01-15
Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unauthorized access to the device.
- CVE-2026-23658HIGHCVSS 8.6EG 8.62026-03-19
Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-23742HIGHCVSS 8.8EG 8.82026-01-16
Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem starts if untrusted users can create lua filters, because of -lua-sources=inline…
- CVE-2026-23927MEDIUMCVSS 5.1EG 5.12026-05-06
A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a n…
- CVE-2026-23958CRITICALCVSS 9.8EG 9.82026-01-22
Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the user’s password as the JWT signing secret. This deterministic secret derivation allows an attacker to brute-force th…
- CVE-2026-24845MEDIUMCVSS 6.5EG 6.52026-01-29
malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 0.10.0 and prior to version 1.20.3, malcontent could be made to expose Docker registry credentials if it scanned a special…
- CVE-2026-25631MEDIUMCVSS 6.5EG 6.52026-02-06
n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validation allowed an authenticated attacker to send requests with credentials to unintended domain…
- CVE-2026-25774MEDIUMCVSS 5.3EG 6.52026-02-27
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-26049MEDIUMCVSS 5.7EG 5.72026-02-20
The web management interface of the device renders the passwords in a plaintext input field. The current password is directly visible to anyone with access to the UI, potentially exposing administrator credentials to unauthorized observ…
- CVE-2026-27003MEDIUMCVSS 5.5EG 5.52026-02-20
OpenClaw is a personal AI assistant. Telegram bot tokens can appear in error messages and stack traces (for example, when request URLs include `https://api.telegram.org/bot<token>/...`). Prior to version 2026.2.15, OpenClaw logged these st…
- CVE-2026-27027MEDIUMCVSS 6.5EG 6.52026-03-06
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-27167MEDIUMCVSS 5.9EG 5.92026-03-01
Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically enable "mocked" OAuth routes when OAuth…
- CVE-2026-27316LOWCVSS 2.7EG 2.72026-04-14
A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentia…
- CVE-2026-27770MEDIUMCVSS 6.5EG 6.52026-03-06
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-27773MEDIUMCVSS 5.3EG 6.52026-02-27
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-27777MEDIUMCVSS 6.5EG 6.52026-03-06
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-28204MEDIUMCVSS 6.5EG 6.52026-03-20
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-28714MEDIUMCVSS 4.8EG 4.82026-03-06
Unnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
- CVE-2026-28909MEDIUMCVSS 6.5EG 6.52026-04-30
Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.
- CVE-2026-28961MEDIUMCVSS 4.6EG 4.62026-05-11
This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. An attacker with physical access to a locked device may be able to view sensitive user information.
- CVE-2026-29128CRITICALCVSS 10.0EG 10.02026-03-05
IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) that are owned by root but world-readable. The configuration files (e.g., zebra.conf, bgpd.c…
- CVE-2026-29872HIGHCVSS 8.2EG 8.22026-03-30
A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19). The affected Streamlit-based GitHub MCP Agent stores user-supplied API tokens in p…
- CVE-2026-30796HIGHCVSS 7.5EG 7.52026-03-05
Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat sync loop modules) …
- CVE-2026-31926MEDIUMCVSS 6.5EG 6.52026-03-20
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-32171HIGHCVSS 8.8EG 8.82026-04-14
Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
- CVE-2026-32315MEDIUMCVSS 5.5EG 5.52026-06-22
motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the configuration file /etc/motioneye/motion.conf with 644 permissions (-rw-r--r--), making it…
- CVE-2026-32606HIGHCVSS 7.6EG 7.62026-03-18
IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd-cryptenroll as used by IncusOS through mkosi allows for an attacker with physical access to the machine to access the …
- CVE-2026-32633CRITICALCVSS 9.1EG 9.12026-03-18
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint returns raw server objects from `GlancesServersList.get_servers_list()`. Those objects are …
- CVE-2026-32634HIGHCVSS 8.1EG 8.12026-03-18
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised server name and the discovered IP address for dynamic servers, but later builds c…
- CVE-2026-32913CRITICALCVSS 9.3EG 9.32026-03-23
OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept…
- CVE-2026-33182HIGHCVSS 7.5EG 7.52026-03-26
Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building the request URL, Saloon combined the connector's base URL with the request endpoint. If the endpoint was a valid absol…
- CVE-2026-33575HIGHCVSS 7.5EG 7.52026-03-29
OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pair endpoint and OpenClaw qr command. Attackers with access to leaked setup codes from chat history, logs, or screenshots…
- CVE-2026-34262MEDIUMCVSS 5.0EG 5.02026-04-14
Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
- CVE-2026-35155HIGHCVSS 7.1EG 7.12026-04-29
Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exists that could allow an authenticated low‑privileged attacker to gain elevated access.
- CVE-2026-35185HIGHCVSS 7.5EG 7.52026-04-06
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is publicly accessible and exposes sensitive information including authentication tokens (user_token), user activity, client …
- CVE-2026-35467HIGHCVSS 7.5EG 7.52026-04-02
The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.
- CVE-2026-3783MEDIUMCVSS 5.3EG 5.32026-03-11
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is redi…
Map vulnerabilities like CWE-522 to your infrastructure
EchelonGraph correlates every CVE — across CWE-522 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →