CWE-522— Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.— MITRE CWE catalog
1,661 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-522page 33 of 34
- CVE-2026-67427HIGHCVSS 8.6EG 8.62026-07-29
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} for any host environment variable without an allowlist or capability policy check, allowing…
- CVE-2026-69805HIGHCVSS 7.5EG 7.52026-09-08
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-7017HIGHCVSS 7.1EG 7.12026-07-07
HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the ca…
- CVE-2026-7038LOWCVSS 3.3EG 3.32026-04-26
A weakness has been identified in tufantunc ssh-mcp up to 1.5.0. Impacted is an unknown function of the file src/index.ts of the component Command Line Handler. This manipulation causes insufficiently protected credentials. The attack is r…
- CVE-2026-71260MEDIUMCVSS 6.5EG 6.52026-08-05
ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (esphome/components/web_server/web_server.cpp), a text entity configured with mode: password (TEXT_MODE_PASSWORD) has its JSO…
- CVE-2026-71293MEDIUMCVSS 6.2EG 6.22026-08-05
Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case for the handle that returns the user's raw two-factor recovery codes with no access restriction.
- CVE-2026-71494MEDIUMCVSS 5.9EG 5.92026-08-21
Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_variables_loader.go and related Terraform Cloud, remote-plan, and Terragrunt registry request paths can attach a c…
- CVE-2026-71511MEDIUMCVSS 6.5EG 6.52026-08-24
Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password verifiers by querying member endpoints. Attackers can c…
- CVE-2026-71577MEDIUMCVSS 6.3EG 6.32026-08-10
A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sensi…
- CVE-2026-71862HIGHCVSS 7.5EG 7.52026-08-21
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting caus…
- CVE-2026-72793HIGHCVSS 8.6EG 8.62026-08-12
SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypted-…
- CVE-2026-72794HIGHCVSS 8.6EG 8.62026-08-12
siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode. Attackers can retrieve the CookieKey value and forge valid session cookies to impersonat…
- CVE-2026-72801HIGHCVSS 7.5EG 7.52026-08-12
SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode. Attackers can retrieve Argon2id salt, cost parameters, password verifiers, and wrapp…
- CVE-2026-72857HIGHCVSS 7.7EG 7.72026-08-13
Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can …
- CVE-2026-7312CRITICALCVSS 7.5EG 10.02026-06-02
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to 15.3.8531, and 15.4.86…
- CVE-2026-7313HIGHCVSS 4.9EG 8.72026-06-02
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. S…
- CVE-2026-73839MEDIUMCVSS 4.6EG 4.62026-08-27
Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the risk of credential compromise through visual or remote observation. This undermines the confidentiality of device acce…
- CVE-2026-75015MEDIUMCVSS 4.9EG 4.92026-09-14
Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators t…
- CVE-2026-75136MEDIUMCVSS 6.1EG 6.12026-09-02
UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to retrieve the biometric unlock key stored in the Windows PasswordVault API without triggering any authentication prompt.…
- CVE-2026-75960HIGHCVSS 8.1EG 8.12026-08-26
Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.
- CVE-2026-76839MEDIUMCVSS 6.5EG 6.52026-08-25
Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit permissions can call offsetGet() on User obj…
- CVE-2026-76846HIGHCVSS 7.5EG 7.52026-08-25
Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit permission can use config.get() or config.toArray() in Twig t…
- CVE-2026-76854MEDIUMCVSS 6.5EG 6.52026-09-15
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l7_web_auth_user_show.cgi related to captive-portal credential handling. Attackers can query this component to obtain captive-portal user crede…
- CVE-2026-76857MEDIUMCVSS 6.5EG 6.52026-09-15
Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure vulnerability in the ddns_wan_list_show.cgi endpoint and related DDNSset_cgi, IGD_GetCgiHandler, and IGD_CgiCall components. Attackers who reach this C…
- CVE-2026-76859MEDIUMCVSS 6.5EG 6.52026-09-15
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi component. Low-privilege attackers can exploit this flaw via ui_config_2.xml and misc.js to disclose router credentials.
- CVE-2026-76871MEDIUMCVSS 6.5EG 6.52026-09-15
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi. Attackers can leverage these components to…
- CVE-2026-76969CRITICALCVSS 9.4EG 9.42026-09-08
@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive cr…
- CVE-2026-77909HIGHCVSS 7.7EG 7.72026-09-08
Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.
- CVE-2026-78555CRITICALCVSS 9.4EG 9.42026-08-24
RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Although the interface displayed only a shortened representation of each key, the full token was embedded in hidden form field…
- CVE-2026-81381HIGHCVSS 7.5EG 7.52026-09-08
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
- CVE-2026-81861MEDIUMCVSS 5.9EG 5.92026-09-11
CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.
- CVE-2026-82070MEDIUMCVSS 6.5EG 6.52026-09-08
A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated user with monitoring privileges to access insufficiently protected credentials from concurrent administrative operations. The same credentials are …
- CVE-2026-82247HIGHCVSS 7.5EG 7.52026-08-28
gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP redirect identity guard…
- CVE-2026-82255MEDIUMCVSS 6.8EG 6.82026-08-28
gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. The vulnerability occurs because credential val…
- CVE-2026-82288HIGHCVSS 7.5EG 7.52026-08-28
Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated att…
- CVE-2026-82433MEDIUMCVSS 6.5EG 6.52026-09-14
Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, that response includes `storm.zookeeper.auth.payload` and the…
- CVE-2026-82434MEDIUMCVSS 6.5EG 6.52026-09-14
Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration verbatim to any call…
- CVE-2026-82786MEDIUMCVSS 6.3EG 6.32026-09-14
Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulnerability is exploited, sensitive information may be restored from a backup file.
- CVE-2026-8368MEDIUMCVSS 6.5EG 6.52026-05-12
LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-su…
- CVE-2026-84179MEDIUMCVSS 6.5EG 6.52026-09-14
Description getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration and returned the result without redaction in the topology_conf field of TopologyPageInfo. The Storm UI copied that value verbat…
- CVE-2026-85700MEDIUMCVSS 6.5EG 6.52026-09-04
Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authenticated user to read admin-defined API keys. Attackers with basic authentication can call GET /tool/{tool_id} or GET /tool…
- CVE-2026-85717MEDIUMCVSS 6.8EG 6.82026-09-17
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and redirect…
- CVE-2026-85719HIGHCVSS 7.5EG 7.52026-09-17
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests using an authenticated SOCKS proxy can expose the proxy's cr…
- CVE-2026-85720MEDIUMCVSS 5.9EG 5.92026-09-17
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can expose pre…
- CVE-2026-86175MEDIUMCVSS 6.5EG 6.52026-09-05
NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backends…
- CVE-2026-86600HIGHCVSS 8.2EG 8.22026-09-08
In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify th…
- CVE-2026-86726MEDIUMCVSS 6.5EG 6.52026-09-08
AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other streamers' active restreams. The endpoint fail…
- CVE-2026-86862MEDIUMCVSS 6.5EG 6.52026-09-17
pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connection…
- CVE-2026-88013LOWCVSS 3.7EG 3.72026-09-10
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches headers configured through --http-headers or headers= to requests in backend/…
- CVE-2026-8810MEDIUMCVSS 6.9EG 6.92026-08-19
On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.
Map vulnerabilities like CWE-522 to your infrastructure
EchelonGraph correlates every CVE — across CWE-522 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →