Weaknesses of type CWE-522

689 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2026-59209HIGHn8n: Shared Credential Header Leak via HTTP Request Pagination ExpressionEPSS 0.4%CVE-2026-21670HIGHA vulnerability allowing a low-privileged user to extract saved SSH credentials.EPSS 0.4%CVE-2026-54618CRITICALObsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the userEPSS 0.4%CVE-2024-31800MEDIUMAuthentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell EPSS 0.4%CVE-2023-50310MEDIUMIBM CICS Transaction Gateway for Multiplatforms information disclosureEPSS 0.4%CVE-2019-10224MEDIUMA flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may diEPSS 0.4%CVE-2026-62684LOWFile Browser: Share API exposes the password hash and bypass tokenEPSS 0.4%CVE-2026-39462CRITICALSenseLive X3050 Insufficiently Protected CredentialsEPSS 0.4%CVE-2024-49396HIGHInsufficiently Protected Credentials in Elvaco M-Bus Metering Gateway CMe3100EPSS 0.4%CVE-2025-15617HIGHWazuh GitHub Actions Workflow Exposure of Sensitive CredentialsEPSS 0.4%CVE-2019-10210MEDIUMPostgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotectedEPSS 0.4%CVE-2026-81861MEDIUMCWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized accEPSS 0.4%CVE-2023-49233HIGHInsufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative VEPSS 0.4%CVE-2026-61516CRITICALNetis NX10 Credential Disclosure via sysinfo Diagnostic EndpointEPSS 0.4%CVE-2025-0498HIGHRockwell Automation FactoryTalk® AssetCentre Data Exposure VulnerabilityEPSS 0.4%CVE-2019-10981In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified that may allow an authenticated local userEPSS 0.4%CVE-2024-12799CRITICALInsufficiently Protected CredentialsEPSS 0.4%CVE-2025-40838MEDIUMEricsson Indoor Connect 8855 - Insufficiently Protected Credentials VulnerabilityEPSS 0.4%CVE-2025-7386MEDIUMInformation exposure vulnerability in Hitachi Storage NavigatorEPSS 0.4%CVE-2024-34883MEDIUMInsufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-serveEPSS 0.4%