CWE-312Base

Cleartext Storage of Sensitive Information

Draft in the CWE catalog · 330 CVEs mapped

330
CVEs mapped
6.2
Median CVSS
What it is

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Recent examples
none
CVE-2026-53603

CVE-2026-53603 - UNKNOWN Severity Vulnerability

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32-byte random hex value sent directly in a cookie and valid for 24 hours. Anyone who can read the database (backup, snapshot, file copy, or SQL-level disclosure) obtains every active session token and can hijack operator sessions directly, with no further authentication. This issue has been patched in version 0.3.8.

no explanation yet
0%
epss
2.2cvss
CVE-2026-73748

CVE-2026-73748 - LOW Severity Vulnerability

A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.

LOWno explanation yet
0%
epss
7.2cvss
CVE-2026-83551

CVE-2026-83551 - HIGH Severity Vulnerability

Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and forge valid integrity signatures for specially crafted function payloads, achieving code execution in another user's pipeline execution context within the same AWS account.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-312
Abstraction
Base
Structure
Simple
Status
Draft
References (10)