CWE•Class•Incomplete•20 recent CVEs
CWE-522Insufficiently Protected Credentials
Description
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Common consequences
- Access Control→Gain Privileges or Assume IdentityAn attacker could gain access to user accounts and access sensitive data used by the user accounts.
Potential mitigations
- Architecture and DesignUse an appropriate security mechanism to protect the credentials.
- Architecture and DesignMake appropriate use of cryptography to protect the credentials.
- ImplementationUse industry standards to protect the credentials (e.g. LDAP, keystore, etc.).
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-165535.42026-07-29CVE-2026-674278.62026-07-29CVE-2026-674269.32026-07-29CVE-2026-674258.62026-07-29CVE-2026-546607.42026-07-29CVE-2026-143542026-07-29CVE-2026-175694.32026-07-27CVE-2026-544225.52026-07-24CVE-2026-480226.52026-07-17CVE-2026-449792026-07-17CVE-2026-161044.32026-07-17CVE-2026-622146.52026-07-17CVE-2026-622136.52026-07-17CVE-2026-622086.52026-07-17CVE-2026-464582026-07-15CVE-2026-482957.52026-07-14CVE-2026-598919.62026-07-14CVE-2026-472826.52026-07-14CVE-2026-623279.12026-07-13CVE-2026-572197.52026-07-10