CWE•Class•Draft•20 recent CVEs
CWE-326Inadequate Encryption Strength
Description
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.
Common consequences
- Access Control,Confidentiality→Bypass Protection Mechanism,Read Application DataAn attacker may be able to decrypt the data using brute force attacks.
Potential mitigations
- Architecture and DesignUse an encryption scheme that is currently considered to be strong by experts in the field.
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-866703.72026-09-08CVE-2023-543563.72026-09-01CVE-2026-175204.82026-08-29CVE-2026-817187.52026-08-27CVE-2026-478426.52026-08-26CVE-2026-790844.32026-08-25CVE-2026-748899.82026-08-17CVE-2026-657775.32026-08-11CVE-2026-92018.82026-08-05CVE-2026-596517.52026-08-03CVE-2026-46482026-07-28CVE-2026-500446.82026-07-23CVE-2026-498522026-07-17CVE-2024-235649.12026-07-17CVE-2026-351466.32026-07-16CVE-2026-453639.12026-07-14CVE-2025-635797.52026-07-09CVE-2026-148685.52026-07-07CVE-2026-78307.42026-07-01CVE-2026-418608.82026-06-04