CWE-798— Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.— MITRE CWE catalog
1,869 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-798page 38 of 38
- CVE-2026-85391CRITICALCVSS 9.8EG 9.82026-09-03
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary…
- CVE-2026-85451HIGHCVSS 7.1EG 7.12026-09-03
MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-reachable peer can enumerate MOOS proce…
- CVE-2026-85544MEDIUMCVSS 6.1EG 6.12026-09-10
Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, ther…
- CVE-2026-8605CRITICALCVSS 9.8EG 9.82026-05-19
In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.
- CVE-2026-86150MEDIUMCVSS 4.1EG 4.12026-09-05
A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be l…
- CVE-2026-86276HIGHCVSS 7.3EG 7.32026-09-07
A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead to hard-coded credentials. The attack c…
- CVE-2026-86464CRITICALCVSS 9.9EG 9.92026-09-08
In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. …
- CVE-2026-86520HIGHCVSS 7.5EG 7.52026-09-18
Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.
- CVE-2026-86555MEDIUMCVSS 6.2EG 6.22026-09-20
The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.
- CVE-2026-86673HIGHCVSS 7.3EG 7.32026-09-08
A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connecti…
- CVE-2026-8876HIGHCVSS 7.3EG 7.32026-06-03
Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These keys decrypt crisis alert keyword data and intervention site data.
- CVE-2026-8982HIGHCVSS 8.1EG 8.12026-07-21
Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the a…
- CVE-2026-8983CRITICALCVSS 9.8EG 9.82026-07-21
Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functi…
- CVE-2026-90509HIGHCVSS 7.3EG 7.32026-09-13
A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The at…
- CVE-2026-9139CRITICALCVSS 9.8EG 9.82026-05-20
Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web configuration interface where authentication is implemented entirely in client-side JavaScript in login.zhtml, exposing…
- CVE-2026-9260CRITICALCVSS 9.8EG 9.82026-06-16
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
- CVE-2026-92787CRITICALCVSS 9.8EG 9.82026-09-16
Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain tr…
- CVE-2026-93969HIGHCVSS 7.3EG 7.32026-09-20
A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. The manipulation leads to hard-coded credentials. The attack is possible to be car…
- CVE-2026-93970HIGHCVSS 7.3EG 7.32026-09-20
A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials. T…
Map vulnerabilities like CWE-798 to your infrastructure
EchelonGraph correlates every CVE — across CWE-798 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →