CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,403 vulnerabilities with CWE-522
CVE-2026-41266 HIGH
Flowise: Sensitive Data Leak in public-chatbotConfig
CVSS 7.5
CVE-2026-6408 LOW
Tanium addressed an information disclosure vulnerability in Tanium Server.
CVSS 2.7
CVE-2026-40173 CRITICAL
Dgraph: Unauthenticated pprof endpoint leaks admin auth token
CVSS 9.4
CVE-2026-32171 HIGH
Azure Logic Apps Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-27316 LOW
Fortinet FortiSandbox <5.0.5 - Info Disclosure
CVSS 2.7
CVE-2026-22576 MEDIUM
FortiSOAR PaaS <7.6.4 - Info Disclosure
CVSS 4.3
CVE-2026-22574 MEDIUM
FortiSOAR PaaS <7.6.4 - Info Disclosure
CVSS 4.1
CVE-2026-34262 MEDIUM
Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
CVSS 5.0
CVE-2026-35185 HIGH
HAX CMS's public /server-status endpoint exposes authentication tokens, user activity, and client IP addresses
CVSS 7.5
CVE-2026-35467 HIGH
Private Key stored as extractable in browser IndexeDB
CVSS 7.5
CVE-2026-4819 MEDIUM
Search Guard audit logs can contain under certain conditions user credentials
CVSS 4.9
CVE-2026-29872 HIGH
awesome-llm-apps e46690f - Info Disclosure
CVSS 8.2
CVE-2026-33575 HIGH
OpenClaw < 2026.3.12 - Long-lived Credential Exposure in Pairing Setup Codes
CVSS 7.5
CVE-2026-33182 HIGH
Saloon is vulnerable to SSRF and credential leakage via absolute URL in endpoint overriding base URL
CVSS 7.5
CVE-2026-32913 CRITICAL
OpenClaw < 2026.3.7 - Custom Authorization Header Leakage via Cross-Origin Redirects
CVSS 9.3
CVE-2026-31926 MEDIUM
IGL-Technologies eParking.fi Insufficiently Protected Credentials
CVSS 6.5
CVE-2026-28204 MEDIUM
CTEK Chargeportal Insufficiently Protected Credentials
CVSS 6.5
CVE-2026-23658 HIGH
Azure DevOps: msazure Elevation of Privilege Vulnerability
CVSS 8.6
CVE-2026-32634 HIGH
Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers
CVSS 8.1
CVE-2026-32633 CRITICAL
Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`
CVSS 9.1
CVE-2026-32606 HIGH
IncusOS <202603142010 LUKS - TPM Policy Encryption Bypass
CVSS 7.6
CVE-2026-21670 HIGH
Veeam Backup & Replication 13.0.0.496-13.0.1 - Insufficiently Protected SSH Credentials
CVSS 7.7
CVE-2026-3783 MEDIUM
curl 7.33.0-8.19.0 - OAuth2 Bearer Token Leak via Redirect with .netrc Hostname Match
CVSS 5.3
CVE-2026-27777 MEDIUM
Mobiliti e-mobi.hu - Unprotected User Data Exposure via Web-Based Mapping Platform
CVSS 6.5
CVE-2026-27027 MEDIUM
Everon api.everon.io - Unprotected Credential Exposure via Web Mapping Platform
CVSS 6.5
Details
Vulnerabilities 1,403