Weaknesses of type CWE-321

362 results

Chave criptográfica hardcoded

É quando a chave ou senha usada para criptografia fica embutida no código-fonte ou binário da aplicação. Qualquer pessoa com acesso ao código (incluindo atacantes que fazem engenharia reversa) consegue extrair a chave e descriptografar todos os dados protegidos por ela, anulando completamente a proteção criptográfica.

Example

Um app mobile que faz login criptografa a senha com uma chave fixa como `const ENCRYPTION_KEY = '12345abc'` no código. Um atacante faz dump do APK, encontra a chave em minutos, e consegue descriptografar todas as senhas armazenadas de todos os usuários.

How to mitigate

Armazene chaves em repositórios seguros (key management systems, vaults como AWS Secrets Manager ou HashiCorp Vault), derive chaves de senhas do usuário com algoritmos fortes (PBKDF2, Argon2), ou use mecanismos de derivação dinâmica. Nunca coloque chaves no código, comentários ou arquivos de configuração versionados.

CVE-2026-81821HIGHAVEVA Pipeline Integrity Monitor Use of hard-coded cryptographic keyEPSS 0.1%CVE-2026-5456MEDIUMAlign Technology My Invisalign App com.aligntech.myinvisalign.emea BuildConfig.java hard-coded keyEPSS 0.1%CVE-2025-4876MEDIUMHardcoded Key Revealed in ConnectWise Password Encryption UtilityEPSS 0.1%CVE-2026-39810MEDIUMA use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosEPSS 0.1%CVE-2026-5420LOWShinrays Games Goods Triple App cats.goods.sort.sorting.games jRwTX.java hard-coded keyEPSS 0.1%CVE-2026-2103HIGHUse of Hard-Coded Cryptographic Key for Password StorageEPSS 0.1%CVE-2026-5310LOWEnter Software Iperius Backup IperiusAccounts.ini hard-coded keyEPSS 0.1%CVE-2026-0754HIGHSIP Service Providers – Possible Impersonation of Poly Voice DeviceEPSS 0.1%CVE-2026-44278LOWA use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions EPSS 0.1%CVE-2025-52601MEDIUMHardcoding sensitive informationEPSS 0.1%CVE-2026-78487MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-codedEPSS 0.1%CVE-2026-80167MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-codedEPSS 0.1%CVE-2026-80057MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-codedEPSS 0.1%CVE-2026-39031MEDIUMLansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded 142-byte static key array to encrypt credentials. An 8-charactEPSS 0.1%CVE-2026-32324HIGHAnviz CX7 Firmware Use of Hard-coded Cryptographic KeyEPSS 0.1%CVE-2026-11347HIGHHardcoded Cryptographic Keys and Weak IV Generation in linqiEPSS 0.1%CVE-2026-50603MEDIUMHard-coded encryption key vulnerability in Acer Agent Service for NitroSense and PredatorSenseEPSS 0.1%CVE-2026-50606LOWHard-coded Encryption Key Vulnerability in Acer System Monitoring for NitroSense and PredatorSense SoftwareEPSS 0.1%CVE-2025-58740HIGHHardcoded Encryption Key Enables Database Credential Access in Milner ImageDirector CaptureEPSS 0.1%CVE-2026-86708CRITICALSensitive data exposureEPSS