CWE-522: Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
529 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-22240 — Plaintext Passwords Vulnerability in BLUVOYIX
- CVE-2025-64420 — Coolify members can see private key of root user
- CVE-2025-54863 — Insufficiently Protected Credentials in Radiometrics VizAir
- CVE-2024-51545 — Username Enumeration
- CVE-2024-12799 — Insufficiently Protected Credentials
- CVE-2025-0867 — Privilege Escalation in MEAC300
- CVE-2025-55306 — GenX_FX authentication bypass in JWT validation
- CVE-2025-54428 — RevelaCode exposes Sensitive MongoDB Atlas URI in .env (potential credential leak)
- CVE-2025-58366 — Onyxia private helm repository credentials are leaked through unauthenticated API
- CVE-2024-5176 — Vulnerability in Welch Allyn Configuration Tool Software
- CVE-2025-6519 — Consistent predictable generation of the password for the default admin user "ONEDAY" to the application services
- CVE-2025-22372 — Insecure password storage in SicommNet BASEC
- CVE-2025-0477 — Rockwell Automation FactoryTalk® AssetCentre Data Exposure Vulnerability
- CVE-2024-37051 — GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ
- CVE-2025-52549 — Predictable root linux password generation
- CVE-2026-32633 — Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`
- CVE-2025-36096 — AIX Insufficiently Protected Credentials
- CVE-2026-23958 — DataEase Vulnerable to Brute-Force Attack on Admin JWT Secret Derived from Password that Enables Full Account Takeover
- CVE-2026-23742 — Skipper arbitrary code execution through lua filters
- CVE-2025-42933 — Insecure Storage of Sensitive Information in SAP Business One (SLD)
Recently published
- CVE-2026-82070 — Insufficiently Protected Credentials in MongoDB Server Diagnostic Reporting Interface
- CVE-2026-86600 — Workload identity attestation generated before login host validation in Snowflake drivers
- CVE-2026-86726 — AVideo through 29.0 Information Disclosure via restreamsActive.json.php
- CVE-2026-61516 — Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint
- CVE-2026-76969 — Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)
- CVE-2026-86175 — NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs
- CVE-2026-53603 — nebula-mesh: Operator session tokens stored in plaintext in the database
- CVE-2026-85700 — Onyx 4.6.6 Custom Tool Secret Header Disclosure via Tool Endpoints
- CVE-2026-8862 — Vulnerabilities exists in IBM Netezza Software
- CVE-2026-75136 — UpSignOn < 7.19.0 Biometric Key Exposure via Windows PasswordVault
- CVE-2026-55860 — MariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
- CVE-2026-55857 — MariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
- CVE-2026-55856 — MariaDB Connector/J: Cleartext password disclosure to a MITM on the initial-handshake
- CVE-2026-55854 — MariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials in mariadb
- CVE-2026-55215 — MariaDB Connector/Node.js: Connector leaks the cleartext password to an MitM despite `ssl: true`
- CVE-2026-82288 — Stable Diffusion WebUI Credential Disclosure via /sdapi/v1/cmd-flags
- CVE-2026-82255 — gitoxide 0.25.4 HTTP Credential Leak via Redirect
- CVE-2026-82247 — gitoxide before 0.37.1 HTTP Basic credential leak via URL parsing
- CVE-2026-61802 — Wazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local/config
- CVE-2026-73839 — Ebyte NE2-D11 Insufficiently Protected Credentials