CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,358 vulnerabilities with CWE-522
CVE-2026-6517 MEDIUM
Mattermost Desktop App fails to restrict the allow list of domains which NTLM credentials are passed
CVSS 6.3
CVE-2026-49949 MEDIUM
CodexBar < 0.33.0 Credential Leakage via HTTP Redirect
CVSS 5.3
CVE-2026-41715 MEDIUM
Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect
CVSS 6.1
CVE-2026-39908 MEDIUM
OpenBullet2 0.3.2 NTLMv2 Hash Disclosure via UNC Path Proxy Source
CVSS 6.5
CVE-2026-46440 CRITICAL
Flowise: Basic Auth Credentials Exposed via API
CVSS 9.1
CVE-2026-46511 HIGH
HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
CVE-2026-7313 HIGH
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity
CVSS 8.7
CVE-2026-7312 CRITICAL
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity
CVSS 10.0
CVE-2026-4387 LOW
Unencrypted storage of authentication state in StrongDM Desktop Application state.kv file
CVE-2026-49379 MEDIUM
Jetbrains TeamCity < 2026.1 - Insufficiently Protected Credentials
CVSS 6.5
CVE-2026-42951 MEDIUM
MacGregor Voyage Data Recorder (VDR) G4e Insufficiently Protected Credentials
CVSS 5.4
CVE-2026-2255 MEDIUM
Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials
CVSS 4.3
CVE-2026-9395 LOW
Besen BS20 EV Charging Station BLE/UDP insufficiently protected credentials
CVSS 3.5
CVE-2026-39968 HIGH
TypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview Endpoint
CVSS 7.1
CVE-2026-0393 MEDIUM
CODESYS Visualization - Insufficiently Protected Credentials
CVSS 6.5
CVE-2026-6345 MEDIUM
Prevent password disclosure and force reset during Slack import
CVSS 6.5
CVE-2026-6253 MEDIUM
curl - Credential Leakage via Proxy Redirect Handling
CVSS 5.9
CVE-2026-43992 CRITICAL
JunoClaw: MCP write tools exposed raw BIP-39 mnemonic as a tool-call parameter
CVSS 9.8
CVE-2026-8368 MEDIUM
LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects
CVSS 6.5
CVE-2026-45091 CRITICAL
sealed-env: TOTP secret embedded in unseal token payload (enterprise mode)
CVSS 9.1
CVE-2026-28961 MEDIUM
macOS < 26.5 - Unprotected User Data Exposure via Physical Access
CVSS 4.6
CVE-2026-42869 CRITICAL
SOCFortress CoPilot: Hardcoded JWT secret allows unauthenticated full admin compromise and lateral movement into all integrated SOC tools
CVSS 10.0
CVE-2026-42295 MEDIUM
Argo Workflows: Exposure of artifact repository credentials
CVSS 4.9
CVE-2026-41506 MEDIUM
go-git Credential leak via cross-host redirect in smart HTTP transport
CVSS 4.7
CVE-2026-23927 MEDIUM
Agent 2 Oracle plugin TNS connection string injection via the 'service' parameter
Details
Vulnerabilities 1,358