Weaknesses of type CWE-522

691 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2026-67426CRITICALFlyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltrationEPSS 0.3%CVE-2024-47161MEDIUMIn JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST APIEPSS 0.3%CVE-2022-36307The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 softwaEPSS 0.3%CVE-2026-54276MEDIUMAIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect ChallengesEPSS 0.3%CVE-2026-1433MEDIUMuniFLOW Universal Login Manager (ULM) Standalone Improper Protection of Sensitive Information Leads to Information DisclosureEPSS 0.3%CVE-2026-14019MEDIUMInappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a EPSS 0.3%CVE-2020-16097HIGHOn controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed EPSS 0.3%CVE-2026-27316LOWA insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbEPSS 0.3%CVE-2026-34262MEDIUMInformation Disclosure Vulnerability in SAP HANA Cockpit and HANA Database ExplorerEPSS 0.3%CVE-2021-47726HIGHNuCom 11N Wireless Router 5.07.90 Privilege Escalation via Configuration BackupEPSS 0.3%CVE-2022-43442MEDIUMPlaintext storage of a password vulnerability exists in +F FS040U software versions v2.3.4 and earlier, which may allow an attacker to obtaiEPSS 0.3%CVE-2026-28204MEDIUMCTEK Chargeportal Insufficiently Protected CredentialsEPSS 0.3%CVE-2025-36096CRITICALAIX Insufficiently Protected CredentialsEPSS 0.3%CVE-2025-14148MEDIUMIBM DevOps Deploy is susceptible to a Insufficiently Protected Credentials vulnerabilityEPSS 0.3%CVE-2026-20791MEDIUMChargemap chargemap.com Insufficiently Protected CredentialsEPSS 0.3%CVE-2024-56354MEDIUMIn JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permissionEPSS 0.3%CVE-2026-82247HIGHgitoxide before 0.37.1 HTTP Basic credential leak via URL parsingEPSS 0.3%CVE-2026-22890MEDIUMEV2GO ev2go.io Insufficiently Protected CredentialsEPSS 0.3%CVE-2026-47662HIGHPathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning via unvalidated manifest output URLsEPSS 0.3%CVE-2026-55188HIGHRustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentialsEPSS 0.3%