Weaknesses of type CWE-798

943 results

Uso de credenciais hardcoded

Credenciais (senhas, chaves de API, tokens) embutidas no código-fonte ou binários da aplicação. O risco é que qualquer pessoa com acesso ao código ou arquivo compilado consegue extrair essas credenciais e abusar dos recursos protegidos, sem depender de quebra de senha ou ataque de força bruta.

Example

Um desenvolvedor coloca a senha do banco de dados como string literal dentro do código: `String connStr = "Server=db.empresa.com;Password=Admin123!";` Quando o código é compilado, a senha fica visível em ferramentas de análise binária ou se o repositório for exposto. Um atacante a encontra e acessa diretamente o banco.

How to mitigate

Armazene credenciais em variáveis de ambiente, secrets managers (como HashiCorp Vault, AWS Secrets Manager) ou arquivos de configuração protegidos fora do repositório. Nunca commite credenciais no Git; use .gitignore e ferramentas de scanning automático para evitar.

CVE-2026-63239MEDIUMHard-coded AWS IAM credentials vulnerabilityEPSS 0.1%CVE-2026-21404MEDIUMNAVTOR NavBox Use of Hard-coded CredentialsEPSS 0.1%CVE-2025-59669MEDIUMA use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0EPSS 0.1%CVE-2025-64778HIGHMirion Medical EC2 Software NMIS BioDose Use of Hard-coded CredentialsEPSS 0.1%CVE-2022-37710HIGHPatterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption KEPSS 0.1%CVE-2025-59180MEDIUMUse of Hard-coded Credentials VulnerabilityEPSS 0.1%CVE-2024-20280MEDIUMCisco UCS Central Software Configuration Backup Static Key VulnerabilityEPSS 0.1%CVE-2025-59095MEDIUMHard-coded Key for PIN Encryption in dormakaba Kaba exos 9300EPSS 0.1%CVE-2025-14115HIGHIBM Sterling Connect:Direct for UNIX Container is affected by vulnerability where hard-coded credentials are embeeded in the product for its internal use.EPSS 0.1%CVE-2026-49323MEDIUMIndian Scout Bobber 2025 WCM-to-ECM weak authenticationEPSS 0.1%CVE-2024-7295HIGHHard-coded credentials used for temporary and cache data encryptionEPSS 0.1%CVE-2026-4219MEDIUMINDEX Conferences & Exhibitions Organization YWF BPOF APGCS App ae.index.apgcs BuildConfig.java hard-coded credentialsEPSS 0.1%CVE-2025-65855MEDIUMThe OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentiaEPSS 0.1%CVE-2026-36606HIGHMercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key using single DES in EPSS 0.1%CVE-2026-4216MEDIUMi-SENS SmartLog App air.SmartLog.android hard-coded credentialsEPSS 0.1%CVE-2025-12708MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.1%CVE-2026-5522MEDIUMQRadar contains hard-coded credentialsEPSS 0.1%CVE-2026-26334HIGHCalero VeraSMART < 2026 R1 Hardcoded Static AES Keys Allow Decryption of Service CredentialsEPSS 0.1%CVE-2025-37112MEDIUMHard-Coded Encryption Keys found in SystemEPSS 0.1%CVE-2026-14866HIGHIBM i Access Client Solutions (ACS) is Affected By Multiple VulnerabilitiesEPSS 0.1%