CWE-522— Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.— MITRE CWE catalog
1,661 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-522page 30 of 34
- CVE-2026-14019MEDIUMCVSS 6.5EG 6.52026-06-30
Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-1433MEDIUMCVSS 4.8EG 4.82026-07-06
uniFLOW Universal Login Manager (ULM) Standalone contains an information disclosure vulnerability that may allow an authenticated administrator to access sensitive configuration information through the ULM Remote User Interface (RUI). Expl…
- CVE-2026-14354HIGHCVSS 8.7EG 8.72026-07-29
CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, potentially leading to compromise of managed devices, when a local privileged attacker lever…
- CVE-2026-14564CRITICALCVSS 9.0EG 9.02026-08-17
Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data. This issue affects Logsign SIEM: from 6.4.97 before 6.4.114.
- CVE-2026-15657MEDIUMCVSS 6.5EG 6.52026-07-30
A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the response body.
- CVE-2026-15806MEDIUMCVSS 6.0EG 6.02026-08-18
The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a request…
- CVE-2026-15977HIGHCVSS 7.5EG 7.52026-07-30
SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the --admin-api-key is configured.
- CVE-2026-16104MEDIUMCVSS 6.5EG 6.52026-07-17
A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sens…
- CVE-2026-16553MEDIUMCVSS 5.4EG 5.42026-07-29
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed some sensitive information to be disclosed to an uninte…
- CVE-2026-17349CRITICALCVSS 9.6EG 9.62026-07-31
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including use…
- CVE-2026-17569MEDIUMCVSS 4.3EG 4.32026-07-27
Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint. This issue affects : * Devol…
- CVE-2026-1966LOWCVSS 2.4EG 2.42026-02-05
YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to e…
- CVE-2026-20234CRITICALCVSS 9.9EG 9.92026-09-16
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security…
- CVE-2026-20359CRITICALCVSS 9.9EG 9.92026-08-19
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address…
- CVE-2026-20435MEDIUMCVSS 4.6EG 4.62026-03-02
In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. Us…
- CVE-2026-20733MEDIUMCVSS 5.3EG 6.52026-02-27
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-20791HIGHCVSS 7.5EG 7.52026-02-27
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-21660CRITICALCVSS 9.8EG 9.82026-02-27
A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and…
- CVE-2026-21670HIGHCVSS 6.5EG 7.72026-03-12
A vulnerability allowing a low-privileged user to extract saved SSH credentials.
- CVE-2026-21766MEDIUMCVSS 5.4EG 5.42026-08-05
The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive information may be written to web server…
- CVE-2026-21852HIGHCVSS 7.5EG 7.52026-01-21
Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before users confirmed trust. An attacker-contr…
- CVE-2026-22043CRITICALCVSS 9.8EG 9.82026-01-08
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in RustFS IAM allows a restricted service account or STS credential to self-issue an unrestr…
- CVE-2026-22240HIGHCVSS 7.5EG 7.52026-01-14
The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP…
- CVE-2026-2255MEDIUMCVSS 4.3EG 4.32026-05-27
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those e…
- CVE-2026-22574MEDIUMCVSS 4.1EG 4.12026-04-14
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 thro…
- CVE-2026-22576MEDIUMCVSS 4.3EG 4.32026-04-14
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 thro…
- CVE-2026-22878MEDIUMCVSS 5.3EG 6.52026-02-27
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-22890MEDIUMCVSS 5.3EG 6.52026-02-27
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-22911HIGHCVSS 7.5EG 7.52026-01-15
Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unauthorized access to the device.
- CVE-2026-23658HIGHCVSS 8.6EG 8.62026-03-19
Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-23742HIGHCVSS 8.8EG 8.82026-01-16
Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem starts if untrusted users can create lua filters, because of -lua-sources=inline…
- CVE-2026-23922MEDIUMCVSS 4.9EG 4.92026-08-18
The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.
- CVE-2026-23927MEDIUMCVSS 6.5EG 6.52026-05-06
A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a n…
- CVE-2026-23958CRITICALCVSS 9.8EG 9.82026-01-22
Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the user’s password as the JWT signing secret. This deterministic secret derivation allows an attacker to brute-force th…
- CVE-2026-24845MEDIUMCVSS 6.5EG 6.52026-01-29
malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 0.10.0 and prior to version 1.20.3, malcontent could be made to expose Docker registry credentials if it scanned a special…
- CVE-2026-25631MEDIUMCVSS 6.5EG 6.52026-02-06
n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validation allowed an authenticated attacker to send requests with credentials to unintended domain…
- CVE-2026-25774MEDIUMCVSS 5.3EG 6.52026-02-27
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-26049MEDIUMCVSS 5.7EG 5.72026-02-20
The web management interface of the device renders the passwords in a plaintext input field. The current password is directly visible to anyone with access to the UI, potentially exposing administrator credentials to unauthorized observ…
- CVE-2026-27003MEDIUMCVSS 5.5EG 5.52026-02-20
OpenClaw is a personal AI assistant. Telegram bot tokens can appear in error messages and stack traces (for example, when request URLs include `https://api.telegram.org/bot<token>/...`). Prior to version 2026.2.15, OpenClaw logged these st…
- CVE-2026-27027MEDIUMCVSS 6.5EG 6.52026-03-06
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-27167MEDIUMCVSS 5.9EG 5.92026-03-01
Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically enable "mocked" OAuth routes when OAuth…
- CVE-2026-27316LOWCVSS 2.7EG 2.72026-04-14
A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentia…
- CVE-2026-27770MEDIUMCVSS 6.5EG 6.52026-03-06
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-27773MEDIUMCVSS 5.3EG 6.52026-02-27
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-27777MEDIUMCVSS 6.5EG 6.52026-03-06
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-28204MEDIUMCVSS 6.5EG 6.52026-03-20
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- CVE-2026-28714MEDIUMCVSS 4.8EG 4.82026-03-06
Unnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
- CVE-2026-28909MEDIUMCVSS 6.5EG 6.52026-04-30
Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.
- CVE-2026-28961MEDIUMCVSS 4.6EG 4.62026-05-11
This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. An attacker with physical access to a locked device may be able to view sensitive user information.
- CVE-2026-29128CRITICALCVSS 10.0EG 10.02026-03-05
IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) that are owned by root but world-readable. The configuration files (e.g., zebra.conf, bgpd.c…
Map vulnerabilities like CWE-522 to your infrastructure
EchelonGraph correlates every CVE — across CWE-522 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →