Falhas do tipo CWE-798

943 resultados

Credenciais codificadas em tempo de compilação

É quando senhas, chaves de API, tokens ou outras credenciais são gravadas diretamente no código-fonte ou em arquivos de configuração sem proteção. O desenvolvedor deixa explícito no binário ou repositório dados que deveriam ser secretos, permitindo que qualquer pessoa com acesso ao código ou ao executável extraia as credenciais e acesse sistemas protegidos.

Exemplo

Um desenvolvedor coloca `const apiKey = 'sk-prod-abc123xyz'` no código JavaScript, ou deixa `<password>admin123</password>` em um arquivo XML dentro da aplicação. Um atacante ou concorrente com acesso ao repositório Git ou ao APK extraído consegue encontrar e usar essas credenciais em produção.

Como mitigar

Armazene credenciais em variáveis de ambiente, cofres de segurança (como AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração externos não versionados. Nunca commite credenciais no repositório; use ferramentas de escaneamento de repositórios para detectar padrões de senhas antes do push.

CVE-2026-42869CRITICALSOCFortress CoPilot: Hardcoded JWT secret allows unauthenticated full admin compromise and lateral movement into all integrated SOC toolsEPSS 0.4%CVE-2025-30113CRITICALAn issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials exist in the APK for Ports 9091 and 9092. TEPSS 0.4%CVE-2025-30122CRITICALAn issue was discovered on ROADCAM X3 devices. It has a uniform default credential set that cannot be modified by users, making it easy for EPSS 0.4%CVE-2025-30123CRITICALAn issue was discovered on ROADCAM X3 devices. The mobile app APK (Viidure) contains hardcoded FTP credentials for the FTPX user account, enEPSS 0.4%CVE-2026-48031CRITICALGo Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token ForgeryEPSS 0.4%CVE-2024-6656HIGHHardcoded Credentals in TNB Mobile Solutions' Cockpit SoftwareEPSS 0.4%CVE-2025-63823CRITICALMy Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass EPSS 0.4%CVE-2024-36480CRITICALUse of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an atEPSS 0.4%CVE-2026-41446CRITICALWattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic EndpointsEPSS 0.4%CVE-2025-65823CRITICALThe Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was developed on. If an aEPSS 0.4%CVE-2024-57811CRITICALIn Eaton X303 3.5.16 - X303 3.5.17 Build 712, an attacker with network access to a XC-303 PLC can login as root over SSH. The root password EPSS 0.4%CVE-2026-18452CRITICALRich Source|DMS+ (Non-Mobile) - Use of Hard-coded CredentialsEPSS 0.4%CVE-2025-71317CRITICALNetMan 204 Hard-coded Backdoor CredentialsEPSS 0.4%CVE-2026-8983CRITICALBackdoor Authentication TokenEPSS 0.4%CVE-2024-46508HIGHyeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEYEPSS 0.4%CVE-2023-46102HIGHThe Android Client application, when enrolled to the AppHub server, connects to an MQTT broker to exchange messages and receive commands toEPSS 0.4%CVE-2025-2342MEDIUMIROAD X5 Mobile App API Endpoint hard-coded credentialsEPSS 0.4%CVE-2026-54767CRITICALWeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.phpEPSS 0.4%CVE-2026-46376CRITICALFreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP InterfaceEPSS 0.4%CVE-2025-57601CRITICALAiKaan Cloud Controller uses a single hardcoded SSH private key and the username `proxyuser` for remote terminal access to all managed IoT/eEPSS 0.4%