CWE•Class•Incomplete•20 recent CVEs
CWE-522Insufficiently Protected Credentials
Description
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Common consequences
- Access Control→Gain Privileges or Assume IdentityAn attacker could gain access to user accounts and access sensitive data used by the user accounts.
Potential mitigations
- Architecture and DesignUse an appropriate security mechanism to protect the credentials.
- Architecture and DesignMake appropriate use of cryptography to protect the credentials.
- ImplementationUse industry standards to protect the credentials (e.g. LDAP, keystore, etc.).
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-818612026-09-11CVE-2026-880133.72026-09-10CVE-2026-813816.52026-09-08CVE-2026-779097.72026-09-08CVE-2026-698057.52026-09-08CVE-2026-649186.52026-09-08CVE-2026-820706.52026-09-08CVE-2026-867266.52026-09-08CVE-2026-866008.22026-09-08CVE-2026-615169.82026-09-08CVE-2026-769699.42026-09-08CVE-2026-861756.52026-09-05CVE-2026-536032026-09-04CVE-2026-857006.52026-09-04CVE-2026-88627.52026-09-03CVE-2026-751366.12026-09-02CVE-2026-558605.92026-08-28CVE-2026-558575.92026-08-28CVE-2026-558565.92026-08-28CVE-2026-558545.92026-08-28