CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,358 vulnerabilities with CWE-522
CVE-2026-42367 MEDIUM
GeoVision LPC2011/LPC2211 Web Interface / ssi.cgi privilege escalation vulnerability via leak of Administrator credentials
CVSS 6.5
CVE-2026-6446 MEDIUM
My Social Feeds <= 1.0.4 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'ttp_get_accounts' AJAX Action
CVSS 5.4
CVE-2026-28909 MEDIUM
Apple macOS <0.12.3 - Info Disclosure
CVSS 6.5
CVE-2026-35155 HIGH
Dell iDRAC10 <1.30.10.50 - Privilege Escalation
CVSS 7.1
CVE-2026-7038 LOW
tufantunc ssh-mcp Command Line index.ts insufficiently protected credentials
CVSS 3.3
CVE-2026-39462 HIGH
SenseLive X3050 Insufficiently Protected Credentials
CVSS 8.1
CVE-2026-41345 MEDIUM
OpenClaw < 2026.3.31 - Authorization Header Leak via Cross-Origin Redirect in Media Download
CVSS 5.3
CVE-2026-41266 HIGH
Flowise: Sensitive Data Leak in public-chatbotConfig
CVSS 7.5
CVE-2026-6408 LOW
Tanium addressed an information disclosure vulnerability in Tanium Server.
CVSS 2.7
CVE-2026-40173 CRITICAL
Dgraph: Unauthenticated pprof endpoint leaks admin auth token
CVSS 9.4
CVE-2026-32171 HIGH
Azure Logic Apps Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-27316 LOW
Fortinet FortiSandbox <5.0.5 - Info Disclosure
CVSS 2.7
CVE-2026-22576 MEDIUM
FortiSOAR PaaS <7.6.4 - Info Disclosure
CVSS 4.3
CVE-2026-22574 MEDIUM
FortiSOAR PaaS <7.6.4 - Info Disclosure
CVSS 4.1
CVE-2026-34262 MEDIUM
Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
CVSS 5.0
CVE-2026-35185 HIGH
HAX CMS's public /server-status endpoint exposes authentication tokens, user activity, and client IP addresses
CVSS 7.5
CVE-2026-35467 HIGH
Private Key stored as extractable in browser IndexeDB
CVSS 7.5
CVE-2026-4819 MEDIUM
Search Guard audit logs can contain under certain conditions user credentials
CVSS 4.9
CVE-2026-29872 HIGH
awesome-llm-apps e46690f - Info Disclosure
CVSS 8.2
CVE-2026-33575 HIGH
OpenClaw < 2026.3.12 - Long-lived Credential Exposure in Pairing Setup Codes
CVSS 7.5
CVE-2026-33182 HIGH
Saloon is vulnerable to SSRF and credential leakage via absolute URL in endpoint overriding base URL
CVSS 7.5
CVE-2026-32913 CRITICAL
OpenClaw < 2026.3.7 - Custom Authorization Header Leakage via Cross-Origin Redirects
CVSS 9.3
CVE-2026-31926 MEDIUM
IGL-Technologies eParking.fi Insufficiently Protected Credentials
CVSS 6.5
CVE-2026-28204 MEDIUM
CTEK Chargeportal Insufficiently Protected Credentials
CVSS 6.5
CVE-2026-23658 HIGH
Azure DevOps: msazure Elevation of Privilege Vulnerability
CVSS 8.6
Details
Vulnerabilities 1,358