CWE-326: Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
145 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-12478 — Non-Compliant TLS Configuration
- CVE-2025-2516 — Use of a weak cryptographic key in the signature verification process in WPS Office
- CVE-2024-32758 — exacqVision - Key exchanges
- CVE-2025-68703 — Jervis has a Salt for PBKDF2 derived from password
- CVE-2025-46409 — Inadequate encryption strength issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If thi
- CVE-2025-7398 — Medium Strength Cipher Suites detected on port on ports 9000 and 8036
- CVE-2026-44523 — Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery
- CVE-2024-5800 — Diffie-Hellman groups with insufficient strength used in SSL/TLS stack of B&R Automation Runtime
- CVE-2024-42163 — Password Manipulation
- CVE-2024-38867 — A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.64), SIPROTEC 5 6MD85 (CP200) (All ve
- CVE-2024-28860 — Insecure IPsec transport encryption in Cilium
- CVE-2026-74889 — openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF
- CVE-2023-54356 — Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites
- CVE-2018-25272 — ELBA5 5.8.0 Remote Code Execution via Database Access
- CVE-2024-28974 — Dell Data Protection Advisor, version(s) 19.9, contain(s) an Inadequate Encryption Strength vulnerability. A low privile
- CVE-2026-45363 — `jwt` (Ruby gem) - empty-key HMAC bypass
- CVE-2026-44351 — fast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypass
- CVE-2024-23564 — HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obta
- CVE-2026-33512 — AVideo has an unauthenticated decrypt oracle leaking any ciphertext
- CVE-2024-29969 — TLS/SSL weak message authentication code ciphers are added by default for port 18082
Recently published
- CVE-2026-86670 — aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash
- CVE-2023-54356 — Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites
- CVE-2026-81718 — openssl_encrypt before 1.4.9 Weak Cryptographic Parameters
- CVE-2026-79084 — Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote a
- CVE-2026-74889 — openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF
- CVE-2026-9201 — Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
- CVE-2026-59651 — BKS keystore accepts legacy version with 16-bit integrity MAC key
- CVE-2026-4648 — Insufficient Encryption Level in CasfID Servicios Tecnológicos NFC Wristbands
- CVE-2026-50044 — Inadequate Encryption Strength in Panduit IntraVUE by Pronetiqs
- CVE-2026-49852 — joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
- CVE-2024-23564 — HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obta
- CVE-2026-35146 — HCL DFXServer is affected by an Unencrypted Communication vulnerability.
- CVE-2026-45363 — `jwt` (Ruby gem) - empty-key HMAC bypass
- CVE-2026-14868 — Weak encryption mechanism for User directory
- CVE-2026-7830 — UltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabling credential interception
- CVE-2026-41860 — CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpReq
- CVE-2026-45787 — electerm's encrypt method not safe enough
- CVE-2026-44523 — Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery
- CVE-2026-44351 — fast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypass
- CVE-2026-33361 — Meari weak XOR obfuscation