CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,403 vulnerabilities with CWE-522
CVE-2026-55431 HIGH
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
CVSS 7.7
CVE-2026-7017 HIGH
HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets
CVSS 7.1
CVE-2026-44938 HIGH
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
CVSS 8.8
CVE-2026-1433 MEDIUM
uniFLOW Universal Login Manager (ULM) Standalone Improper Protection of Sensitive Information Leads to Information Disclosure
CVE-2026-9079 CRITICAL
curl - Stale Proxy Password Leak
CVSS 9.8
CVE-2026-8926 CRITICAL
curl - Password Leak with Netrc and User in URL
CVSS 9.1
CVE-2026-14019 MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via Passwords Feature
CVSS 6.5
CVE-2026-56783 MEDIUM
Parseable < 2.9.2 - Cleartext Credential Exposure in Notification Target API
CVSS 6.5
CVE-2026-55188 HIGH
RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials
CVSS 8.2
CVE-2026-45407 MEDIUM
Dokku: Git Credentials in .netrc Stored World-Readable Due to Premature touch
CVSS 5.0
CVE-2026-44622 MEDIUM
EVoke Systems EVoke CSMS Insufficiently Protected Credentials
CVSS 6.5
CVE-2026-55180 MEDIUM
pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
CVSS 6.5
CVE-2026-50017 MEDIUM
pnpm binds unscoped user-level npm auth credentials to a repository-selected registry
CVSS 6.5
CVE-2026-9650 HIGH
Schneider Electric EasyLogic T150 (formerly Saitel Dr) Remote Terminal Unit & Controller - Insufficiently Protected Credentials
CVSS 7.5
CVE-2026-32315 MEDIUM
motionEye: World-Readable Configuration File Exposes Admin Password Hash
CVSS 5.5
CVE-2026-54276 MEDIUM
AIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges
CVSS 6.1
CVE-2026-53632 MEDIUM
NTLMv2 hash disclosure via UNC path handling on Windows
CVE-2026-53840 HIGH
OpenClaw < 2026.5.12 - Custom Header Leakage via MCP Streamable HTTP Cross-Origin Redirects
CVSS 7.1
CVE-2026-6517 MEDIUM
Mattermost Desktop App fails to restrict the allow list of domains which NTLM credentials are passed
CVSS 6.3
CVE-2026-49949 MEDIUM
CodexBar < 0.33.0 Credential Leakage via HTTP Redirect
CVSS 5.3
CVE-2026-41715 MEDIUM
Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect
CVSS 6.1
CVE-2026-39908 MEDIUM
OpenBullet2 0.3.2 NTLMv2 Hash Disclosure via UNC Path Proxy Source
CVSS 6.5
CVE-2026-46440 CRITICAL
Flowise: Basic Auth Credentials Exposed via API
CVSS 9.1
CVE-2026-46511 HIGH
HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
CVE-2026-7313 HIGH
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity
CVSS 8.7
Details
Vulnerabilities 1,403