CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

457 vulnerabilities with CWE-326
CVE-2026-4648 MEDIUM
Insufficient Encryption Level in CasfID Servicios Tecnológicos NFC Wristbands
CVE-2026-50044 MEDIUM
Inadequate Encryption Strength in Panduit IntraVUE by Pronetiqs
CVSS 6.8
CVE-2026-49852 HIGH
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
CVE-2026-35146 MEDIUM
HCL DFXServer is affected by an Unencrypted Communication vulnerability.
CVSS 6.3
CVE-2026-45363 CRITICAL
`jwt` (Ruby gem) - empty-key HMAC bypass
CVSS 9.1
CVE-2026-14868 MEDIUM
arcinfo PcVue - Weak Encryption Mechanism for User Directory
CVSS 5.5
CVE-2026-7830 HIGH
UltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabling credential interception
CVSS 7.4
CVE-2026-41860 HIGH
Cloud Foundry Foundation Bosh < 282.1.9 - Inadequate Encryption Strength
CVSS 8.8
CVE-2026-8878 HIGH
Securly Chrome Extension < 3.0.7 - Unauthenticated Sensitive Data Exposure via Public Endpoints
CVSS 7.5
CVE-2026-45787 CRITICAL
electerm's encrypt method not safe enough
CVSS 9.1
CVE-2026-44523 CRITICAL
Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery
CVSS 10.0
CVE-2026-44351 CRITICAL
fast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypass
CVSS 9.1
CVE-2026-33361 HIGH
Meari weak XOR obfuscation
CVSS 7.5
CVE-2026-5363 HIGH
Use of weak cryptographic key in TP-Link Archer C7
CVSS 8.8
CVE-2026-5889 MEDIUM
Google Chrome <147.0.7727.55 - Info Disclosure
CVSS 4.3
CVE-2026-39349 LOW
OrangeHRM Uses AES-ECB for Sensitive Data Encryption Enables Pattern Disclosure
CVSS 2.7
CVE-2026-28377 HIGH
S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern)
CVSS 7.5
CVE-2026-33512 HIGH
WWBN AVideo <=26.0 - Info Disclosure
CVSS 7.5
CVE-2026-33488 HIGH
AVideo <=26.0 LoginControl PGP - Two-Factor Authentication Bypass
CVSS 7.4
CVE-2026-0510 LOW
NetWeaver Application Server for Java - Info Disclosure
CVSS 3.0
CVE-2025-63579 HIGH
Kyocera TASKalfa Printers - Unauthenticated Sensitive Information Exposure and Encryption Bypass via Address Book Export
CVSS 7.5
CVE-2025-1241 MEDIUM
Encryption vulnerable to brute-force decryption in GoAnywhere MFT
CVSS 5.8
CVE-2025-36379 MEDIUM
IBM Security QRadar EDR 3.12-3.12.23 - Info Disclosure
CVSS 5.9
CVE-2025-68703 HIGH
Jervis < 2.2 - Inadequate Encryption Strength via Predictable Salt Derivation
CVSS 7.5
CVE-2025-65295 HIGH
Aqara Hub <4.1.9_0027-4.3.6_0025 - RCE
CVSS 8.1
Details
Vulnerabilities 457