VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 71 of 74
  • CVE-2012-5627Oct 1, 2013
    risk 0.04cvss epss 0.11

    Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force…

  • CVE-2026-0290LowAug 13, 2026
    risk 0.03cvss epss 0.00

    An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data.

  • CVE-2026-0289LowAug 13, 2026
    risk 0.03cvss epss 0.00

    A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls.

  • CVE-2026-15977HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the --admin-api-key is configured.

  • CVE-2026-15657MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the response body.

  • CVE-2026-16553MedJul 29, 2026
    risk 0.00cvss 5.4epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed some sensitive information to be disclosed to an unintended host due to improper handling of…

  • CVE-2026-14354HigJul 29, 2026
    risk 0.00cvss epss 0.00

    CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, potentially leading to compromise of managed devices, when a local privileged attacker leverages weaknesses in the handling and…

  • CVE-2026-17569MedJul 27, 2026
    risk 0.00cvss 4.3epss 0.00

    Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint. This issue affects : * Devolutions Server 2026.2.4.0 through…

  • CVE-2026-62214MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot tokens and credentials by failing to properly validate serviceUrl parameters. Attackers can supply malicious serviceUrl values…

  • CVE-2026-62213MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should remain within the trusted…

  • CVE-2026-62208MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization. Impact depends on…

  • CVE-2026-46458HigJul 15, 2026
    risk 0.00cvss epss 0.00

    ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed via static HTTP. This allows an unauthenticated remote attacker to retrieve plaintext service account and SMTP credentials by requesting specific XML files from…

  • CVE-2026-48295HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information. An attacker could leverage this vulnerability to gain unauthorized read access. Exploitation of this issue does not require user…

  • CVE-2026-47282MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-62327CriJul 13, 2026
    risk 0.00cvss 9.1epss 0.00

    9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single unauthenticated request to the /api/usage/stats endpoint.…

  • CVE-2026-59209MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a shared workflow could read credential-populated headers exposed via the $request object inside an HTTP Request node's pagination…

  • CVE-2026-59261HigJul 8, 2026
    risk 0.00cvss 7.1epss 0.00

    OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should remain within trusted…

  • CVE-2026-56843CriJul 8, 2026
    risk 0.00cvss 9.9epss 0.00

    Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only for certain lookup filters and schema validation is bypassed for legacy protocol…

  • CVE-2026-55431HigJul 8, 2026
    risk 0.00cvss 7.7epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder open app` opens external workspace-app URLs without validating the scheme or host. When an external app URL contains the…

  • CVE-2026-44938HigJul 7, 2026
    risk 0.00cvss 8.8epss 0.00

    A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace. An attacker with git push access…