CWE-798— Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.— MITRE CWE catalog
1,780 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-798page 34 of 36
- CVE-2025-9806MEDIUMCVSS 6.4EG 6.42025-09-02
A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded cred…
- CVE-2026-0622MEDIUMCVSS 6.5EG 6.52026-01-20
Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset
- CVE-2026-10557CRITICALCVSS 9.8EG 9.82026-06-12
The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are readily extractable via APK decompilation.…
- CVE-2026-11414CRITICALCVSS 9.8EG 9.82026-06-05
A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical across all installations, an unauthenticated network attacker who can reach the server can for…
- CVE-2026-11746CRITICALCVSS 9.4EG 9.42026-06-22
A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. Th…
- CVE-2026-11849CRITICALCVSS 9.8EG 9.82026-06-12
The iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing unauthenticated remote attackers to exploit hard-coded credentials to gain administrative privileges on the database.
- CVE-2026-12001MEDIUMCVSS 5.2EG 5.22026-07-27
A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is embedded within a password file in the f…
- CVE-2026-1221CRITICALCVSS 9.8EG 9.82026-01-20
PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to the database using hardcoded database credentials stored in the firmwa…
- CVE-2026-1233HIGHCVSS 7.5EG 7.52026-04-04
The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing hardcoded MySQL database credentials f…
- CVE-2026-12628CRITICALCVSS 9.1EG 9.12026-06-22
IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manage…
- CVE-2026-13446CRITICALCVSS 9.8EG 9.82026-07-17
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal dat…
- CVE-2026-13463HIGHCVSS 7.5EG 7.52026-07-28
IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.
- CVE-2026-13728MEDIUMCVSS 4.4EG 4.42026-07-03
In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 20…
- CVE-2026-13768CRITICALCVSS 10.0EG 10.02026-07-03
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to thi…
- CVE-2026-14807CRITICALCVSS 9.8EG 9.82026-07-06
ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code and obtain the database account and password.
- CVE-2026-1610HIGHCVSS 8.1EG 8.12026-01-29
A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. Performing a manipulation results in hard-coded credentials. The attack is possible to be …
- CVE-2026-1612MEDIUMCVSS 6.9EG 6.92026-03-30
AL-KO Robolinho Update Software has hard-coded AWS Access and Secret keys that allow anyone to access AL-KO's AWS bucket. Using the keys directly might give the attacker greater access than the app itself. Key grants AT LEAST read access t…
- CVE-2026-1958HIGHCVSS 8.7EG 8.72026-03-23
Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an unauthorized attacker access to several internal services. Critically, this included access to the FTP server that hosted the application's update packages. The…
- CVE-2026-20111MEDIUMCVSS 4.8EG 4.82026-02-04
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. …
- CVE-2026-2103HIGHCVSS 7.8EG 7.12026-02-06
Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys are identical across all installations. An attacker with a…
- CVE-2026-21404MEDIUMCVSS 6.3EG 6.32026-06-04
NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can extract credentials to bypass the intende…
- CVE-2026-22312HIGHCVSS 8.6EG 8.62026-06-16
The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration and execute some commands (e.g. system re…
- CVE-2026-22769CRITICALCVSS 10.0EG 10.0⚠ KEV2026-02-17
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potenti…
- CVE-2026-22900CRITICALCVSS 9.8EG 9.82026-03-20
A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: …
- CVE-2026-22911MEDIUMCVSS 7.5EG 5.32026-01-15
Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unauthorized access to the device.
- CVE-2026-23647CRITICALCVSS 9.8EG 9.82026-02-17
Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication to the underlying Linux system. Multiple local user accounts, including accounts with admi…
- CVE-2026-23781CRITICALCVSS 9.8EG 9.82026-04-10
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the application package. If left unchanged, these credentials can be easily obtained and may allow…
- CVE-2026-24346CRITICALCVSS 9.1EG 9.12026-01-27
Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web application
- CVE-2026-24444CRITICALCVSS 9.8EG 9.82026-05-28
SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interface recovery endpoints (mgmt.php, npcmd.php) that allows unauthenticated attackers to gain …
- CVE-2026-24448CRITICALCVSS 9.8EG 9.82026-03-11
Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access.
- CVE-2026-24840HIGHCVSS 8.8EG 8.02026-01-28
Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in the provided installation script (located at https://dokploy.com/install.sh, line 154) uses a hardcoded password when cre…
- CVE-2026-25202CRITICALCVSS 9.8EG 9.82026-02-02
The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21.1090.1.
- CVE-2026-25600MEDIUMCVSS 6.4EG 6.42026-06-01
The PDBM application relies on a static, hard‑coded secret embedded in the PDBM.exe executable. This secret is used by the application’s encryption routines, including the function responsible for decrypting credentials stored in th…
- CVE-2026-25601MEDIUMCVSS 6.4EG 6.42026-04-01
A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contained a hardcoded cryptographic key within the Mx.Web.ComponentModel.dll component. When the option to store domain passw…
- CVE-2026-25803CRITICALCVSS 9.8EG 9.82026-02-06
3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first initialization. Attackers with network a…
- CVE-2026-2616HIGHCVSS 9.8EG 8.82026-02-17
A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface. The manipulation leads to hard-coded credentials. The attack needs to be initiated withi…
- CVE-2026-26218CRITICALCVSS 9.8EG 9.82026-02-12
newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema a…
- CVE-2026-26334HIGHCVSS 8.5EG 8.52026-02-13
Calero VeraSMART versions prior to 2026 R1 contain hardcoded static AES encryption keys within Veramark.Framework.dll (Veramark.Core.Config class). These keys are used to encrypt the password of the service account stored in C:\\VeraSMART…
- CVE-2026-2635HIGHCVSS 7.3EG 7.32026-02-20
MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The…
- CVE-2026-2702LOWCVSS 3.1EG 3.12026-02-19
A security flaw has been discovered in Beetel 777VR1 up to 01.00.09. This issue affects some unknown processing of the component WPA2 PSK. Performing a manipulation results in hard-coded credentials. The attacker must have access to the lo…
- CVE-2026-27073HIGHCVSS 7.5EG 7.52026-03-25
Use of Hard-coded Credentials vulnerability in Addi Addi – Cuotas que se adaptan a ti buy-now-pay-later-addi allows Password Recovery Exploitation.This issue affects Addi – Cuotas que se adaptan a ti: from n/a through <= 2.0.4.
- CVE-2026-27167MEDIUMCVSS 5.9EG 5.92026-03-01
Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically enable "mocked" OAuth routes when OAuth…
- CVE-2026-27507CRITICALCVSS 9.8EG 9.82026-02-24
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain hard-coded administrative credentials that cannot be changed by users. Knowledge of these credentials allows full administrative access to the device.
- CVE-2026-27785HIGHCVSS 8.8EG 8.82026-04-28
Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.
- CVE-2026-28255CRITICALCVSS 9.8EG 9.82026-03-12
A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.
- CVE-2026-28674HIGHCVSS 7.2EG 7.22026-03-18
xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the `AdminPaymentPluginUpload` endpoint lets admins upload any file to `plugins/payment/`. It only checks a h…
- CVE-2026-28776CRITICALCVSS 9.8EG 9.82026-03-04
International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote unauthenticated attacker can use these trivial, undocumented credentials to access the sy…
- CVE-2026-28777CRITICALCVSS 9.8EG 9.82026-03-04
International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropp…
- CVE-2026-28778CRITICALCVSS 9.8EG 9.82026-03-04
International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the `xd` user account. A remote unauthenticated attacker can log in via FTP using these credentia…
- CVE-2026-29023HIGHCVSS 7.3EG 7.32026-03-09
Keygraph Shannon contains a hard-coded API key in its router configuration that, when the router component is enabled and exposed, allows network attackers to authenticate using the publicly known static key. An attacker able to reach the …
Map vulnerabilities like CWE-798 to your infrastructure
EchelonGraph correlates every CVE — across CWE-798 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →