Weaknesses of type CWE-798

943 results

Uso de credenciais hardcoded

Credenciais (senhas, chaves de API, tokens) embutidas no código-fonte ou binários da aplicação. O risco é que qualquer pessoa com acesso ao código ou arquivo compilado consegue extrair essas credenciais e abusar dos recursos protegidos, sem depender de quebra de senha ou ataque de força bruta.

Example

Um desenvolvedor coloca a senha do banco de dados como string literal dentro do código: `String connStr = "Server=db.empresa.com;Password=Admin123!";` Quando o código é compilado, a senha fica visível em ferramentas de análise binária ou se o repositório for exposto. Um atacante a encontra e acessa diretamente o banco.

How to mitigate

Armazene credenciais em variáveis de ambiente, secrets managers (como HashiCorp Vault, AWS Secrets Manager) ou arquivos de configuração protegidos fora do repositório. Nunca commite credenciais no Git; use .gitignore e ferramentas de scanning automático para evitar.

CVE-2022-41398HIGHThe optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr iEPSS 0.5%CVE-2022-45425HIGHSome Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the AES crypto key by expEPSS 0.5%CVE-2025-57602CRITICALInsufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined with the use of a shared, hardcoded SSH privEPSS 0.5%CVE-2026-71801CRITICALAn issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core EPSS 0.5%CVE-2026-56278CRITICALFlowise - Session Hijacking via Weak Default Express Session SecretEPSS 0.5%CVE-2026-22911MEDIUMFirmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unEPSS 0.5%CVE-2024-53614MEDIUMA hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attackers to access sensitive data and execute arbitrary commands with elevEPSS 0.5%CVE-2026-5189CRITICALNexus Repository 3 - Hardcoded Credential in Internal Database ComponentEPSS 0.5%CVE-2024-23685MEDIUMFOLIO mod-remote-storage Hard Coded CredentialsEPSS 0.5%CVE-2025-8857CRITICALChanging|Clinic Image System - Use of Hard-coded CredentialsEPSS 0.5%CVE-2025-51536CRITICALAustrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.EPSS 0.5%CVE-2024-39374CRITICALUse of Hard-coded Credentials in TELSAT marKoni FM TransmitterEPSS 0.5%CVE-2021-35252HIGHCommon Key Vulnerability in Serv-U FTP ServerEPSS 0.5%CVE-2025-46274CRITICALPlanet Technology Network Products Use of Hard-coded CredentialsEPSS 0.5%CVE-2025-65730HIGHAuthentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in 0.62.19, uses a hardcoded secret for signing JWT tokens usedEPSS 0.5%CVE-2025-1242CRITICALAdministrative Credentials Can Be Extracted Through Gardyn API ResponsesEPSS 0.5%CVE-2024-33895MEDIUMCosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parametersEPSS 0.5%CVE-2023-4539HIGHHardcoded password in Comarch ERP XLEPSS 0.5%CVE-2024-50688CRITICALSunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user acEPSS 0.5%CVE-2024-28778MEDIUMIBM Cognos Controller information disclosureEPSS 0.5%