Weaknesses of type CWE-522

691 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2026-41345MEDIUMOpenClaw < 2026.3.31 - Authorization Header Leak via Cross-Origin Redirect in Media DownloadEPSS 0.3%CVE-2025-41682HIGHCredential Disclosure via Insecure Storage on Charge ControllerEPSS 0.3%CVE-2025-6081MEDIUMPass-back attack in Konica Minolta bizhub 227 multifunctional printersEPSS 0.3%CVE-2026-27770MEDIUMePower epower.ie Insufficiently Protected CredentialsEPSS 0.3%CVE-2026-76969CRITICALCredential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)EPSS 0.3%CVE-2025-10879HIGHInsufficiently Protected Credentials in Dingtian DT-R002EPSS 0.3%CVE-2026-31926MEDIUMIGL-Technologies eParking.fi Insufficiently Protected CredentialsEPSS 0.3%CVE-2026-26049MEDIUMJinan USR IOT Technology Limited (PUSR) USR-W610 Insufficiently Protected CredentialsEPSS 0.3%CVE-2024-39879MEDIUMIn JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settingsEPSS 0.3%CVE-2026-52855CRITICALWings exposes node configuration secrets through egg configuration-file templatingEPSS 0.3%CVE-2026-85700HIGHOnyx 4.6.6 Custom Tool Secret Header Disclosure via Tool EndpointsEPSS 0.3%CVE-2026-55765HIGHCloudNativePG: Cleartext role passwords recorded in pg_stat_statements allow privileged tenant roles to recover the PostgreSQL superuser credential and achieve RCE in the database podEPSS 0.3%CVE-2024-53832MEDIUMA vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V05.30). The affected devices contain a securEPSS 0.3%CVE-2025-13478HIGHCache Misconfiguration Leading to Cross-User Data ExposureEPSS 0.3%CVE-2026-0689MEDIUMXIQ‑SE NAC Admin Credential Exposure via HTTP ResponseEPSS 0.3%CVE-2024-37362MEDIUMHitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected CredentialsEPSS 0.3%CVE-2025-12461MEDIUMUnprotected access to parts of the application in Epsilon RH by Grupo CastillaEPSS 0.3%CVE-2026-42367MEDIUMGeoVision LPC2011/LPC2211 Web Interface / ssi.cgi privilege escalation vulnerability via leak of Administrator credentialsEPSS 0.3%CVE-2026-32634HIGHGlances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed ServersEPSS 0.3%CVE-2024-7755HIGHHMS Networks EWON FLEXY 202 Insufficiently Protected CredentialsEPSS 0.3%