CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,752 vulnerabilities with CWE-798
CVE-2026-63239 MEDIUM
Three Learning Koollab LMS - Hard-Coded AWS IAM Credentials Vulnerability
CVSS 5.4
CVE-2026-13463 HIGH
Due to use of IBM Storage Protect, IBM Cloud Pak System is affected by vulnerability []
CVSS 7.5
CVE-2026-12001 MEDIUM
TP-Link TL-WR845N/TL-WR850N/Archer C20/Archer MR200 - Hardcoded Credentials
CVE-2026-55579 CRITICAL
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
CVSS 9.8
CVE-2026-65879 CRITICAL
Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1
CVSS 9.8
CVE-2026-8983 CRITICAL
Autel MaxiCharger Single - Backdoor Authentication Token
CVE-2026-8982 CRITICAL
Autel MaxiCharger Single - Hard-Coded / Backdoor Accounts
CVE-2026-47410 CRITICAL
praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset
CVSS 9.8
CVE-2026-47255 HIGH
AgenticMail API/storage and outbound relay hardening
CVSS 8.2
CVE-2026-13446 CRITICAL
IBM Langflow OSS 1.0.0-1.10.1 - Hard-Coded Credentials
CVSS 9.8
CVE-2026-45336 CRITICAL
HireFlow: Use of Hard-coded Credentials
CVSS 10.0
CVE-2026-49352 CRITICAL
9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass
CVSS 9.8
CVE-2026-61740 CRITICAL
LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
CVE-2026-61684 HIGH
FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default INVOKE_TOKEN_SECRET='token')
CVE-2026-37270 CRITICAL
Trueview T18161-AF 4.9.60.0 - Unauthenticated Auth Bypass via Hardcoded Creds & Improper Validation
CVSS 9.8
CVE-2026-57172 HIGH
DataEase: Hardcoded JWT Signing Secret in ShareLink
CVE-2026-14807 CRITICAL
PROG MIS|ERP App - Use of Hard-coded Credentials
CVSS 9.8
CVE-2026-13768 CRITICAL
Gardyn IoT Hub Use of Hard-coded Credentials
CVSS 10.0
CVE-2026-13728 MEDIUM
WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resource Credential Database
CVSS 4.4
CVE-2026-7839 CRITICAL
UltraVNC repeater ships hardcoded default admin password allowing unauthenticated admin access
CVSS 9.1
CVE-2026-56278 CRITICAL
Flowise - Session Hijacking via Weak Default Express Session Secret
CVSS 9.1
CVE-2026-50110 CRITICAL
Use of Hard-coded Credentials in StoneFly Storage Concentrator
CVSS 9.2
CVE-2026-31928 HIGH
Daktronics Controller Firmware Use of Hard-coded Credentials
CVSS 8.1
CVE-2026-46386 CRITICAL
OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`
CVSS 9.9
CVE-2026-56269 MEDIUM
Flowise - Weak Default Token Hash Secret in JWT Token Encryption
CVSS 4.6
Details
Vulnerabilities 1,752
Exploit Likelihood High