CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,403 vulnerabilities with CWE-522
CVE-2026-16553 MEDIUM
Insufficiently Protected Credentials in GitLab
CVSS 5.4
CVE-2026-67427 HIGH
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
CVSS 8.6
CVE-2026-67426 CRITICAL
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
CVSS 9.3
CVE-2026-67425 HIGH
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
CVSS 8.6
CVE-2026-54660 HIGH
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
CVSS 7.4
CVE-2026-14354 HIGH
Schneider Electric EcoStruxure™ Cybersecurity Admin Expert - Insufficiently Protected Credentials
CVE-2026-17569 MEDIUM
Devolutions Server - Insufficiently Protected Credentials
CVSS 4.3
CVE-2026-54422 MEDIUM
Openstack Ironic Python Agent - Insufficiently Protected Credentials
CVSS 5.5
CVE-2026-48022 MEDIUM
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
CVSS 6.5
CVE-2026-44979 MEDIUM
@hapi/wreck : Sensitive `Proxy-Authorization` header leaked across cross-hostname redirects
CVE-2026-16104 MEDIUM
Keycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only admins
CVSS 4.3
CVE-2026-62214 MEDIUM
OpenClaw < 2026.5.28 Bot Framework SSRF via serviceUrl Parameter Validation
CVSS 6.5
CVE-2026-62213 MEDIUM
OpenClaw < 2026.5.27 Token Leakage via MS Teams Outbound Requests
CVSS 6.5
CVE-2026-62208 MEDIUM
OpenClaw < 2026.6.5 Authorization Header Forwarding via SSE
CVSS 6.5
CVE-2026-46458 HIGH
Credential exposure in ICU Scandinavia Boomerang
CVE-2026-48295 HIGH
CAI Content Credentials | Insufficiently Protected Credentials (CWE-522)
CVSS 7.5
CVE-2026-59891 CRITICAL
Credential confusion in  @sigstore/oci  can leak registry credentials to an attacker-controlled registry
CVSS 9.6
CVE-2026-47282 MEDIUM
GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
CVSS 6.5
CVE-2026-62327 CRITICAL
9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats
CVSS 9.1
CVE-2026-57219 HIGH
RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations
CVSS 7.5
CVE-2026-55885 MEDIUM
Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
CVSS 6.8
CVE-2026-59209 MEDIUM
n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
CVSS 6.5
CVE-2026-11827 MEDIUM
Insufficiently Protected Credentials in GitLab
CVSS 4.9
CVE-2026-59261 HIGH
OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files
CVSS 7.1
CVE-2026-56843 CRITICAL
Webpros Plesk < 18.0.78.4 - Insufficiently Protected Credentials
CVSS 9.9
Details
Vulnerabilities 1,403