CWE•Class•Incomplete•20 recent CVEs
CWE-922Insecure Storage of Sensitive Information
Description
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.
Common consequences
- Confidentiality→Read Application Data,Read Files or DirectoriesAttackers can read sensitive information by accessing the unrestricted storage mechanism.
- Integrity→Modify Application Data,Modify Files or DirectoriesAttackers can overwrite sensitive information by accessing the unrestricted storage mechanism.
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-465112026-06-05CVE-2026-55155.52026-05-27CVE-2026-72574.42026-05-12CVE-2026-408688.12026-04-21CVE-2026-261527.02026-04-14CVE-2026-56665.32026-04-06CVE-2026-56505.32026-04-06CVE-2025-107345.32026-03-23CVE-2025-104646.52026-02-09CVE-2025-116452.42025-10-12CVE-2025-116442.02025-10-12CVE-2024-55987.52024-06-29CVE-2024-37235.32024-06-11CVE-2023-67484.32024-06-11CVE-2024-55997.52024-06-07CVE-2024-42135.32024-05-14CVE-2024-37175.32024-05-02CVE-2023-69625.32024-05-02CVE-2024-36785.32024-04-26CVE-2024-37335.32024-04-25