CWE-311Class1 in KEV

Missing Encryption of Sensitive Data

Draft in the CWE catalog · 274 CVEs mapped

274
CVEs mapped
1
In KEV
6.1
Median CVSS
What it is

The product does not encrypt sensitive or critical information before storage or transmission.

Recent examples
4.3cvss
CVE-2026-84676

CVE-2026-84676 - MEDIUM Severity Vulnerability

Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

MEDIUMno explanation yet
0%
epss
7.5cvss
CVE-2026-81688

CVE-2026-81688 - HIGH Severity Vulnerability

openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can read this hash without the password to confirm guessed plaintexts offline or fingerprint identical plaintexts across separately-encrypted files.

HIGHno explanation yet
0%
epss
4.6cvss
CVE-2026-81681

CVE-2026-81681 - MEDIUM Severity Vulnerability

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with AES-256-GCM encryption and write a marker declaring the workspace encrypted, but the workspace directory is actually stored in cleartext and the derived encryption key is never applied to it. A user who trusts the branding and places files in the workspace leaves them unencrypted on the removable media, so an attacker with physical access to the media can read the sensitive files. Fixed in 1.4.9, which seals the workspace into an authenticated AES-256-GCM vault.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-311
Abstraction
Class
Structure
Simple
Status
Draft
References (5)