CWE•Class•Draft•20 recent CVEs
CWE-326Inadequate Encryption Strength
Description
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.
Common consequences
- Access Control,Confidentiality→Bypass Protection Mechanism,Read Application DataAn attacker may be able to decrypt the data using brute force attacks.
Potential mitigations
- Architecture and DesignUse an encryption scheme that is currently considered to be strong by experts in the field.
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-46482026-07-28CVE-2026-500446.82026-07-23CVE-2026-498522026-07-17CVE-2024-235649.12026-07-17CVE-2026-351466.32026-07-16CVE-2026-453639.12026-07-14CVE-2025-635797.52026-07-09CVE-2026-148685.52026-07-07CVE-2026-78307.42026-07-01CVE-2026-418608.82026-06-04CVE-2026-88787.52026-06-03CVE-2026-457879.12026-05-28CVE-2026-4452310.02026-05-14CVE-2026-443519.12026-05-13CVE-2026-333617.52026-05-11CVE-2018-252729.82026-04-22CVE-2025-12415.82026-04-21CVE-2026-53638.82026-04-16CVE-2026-58894.32026-04-08CVE-2026-393492.72026-04-07