CWE-321Variant1 in KEV

Use of Hard-coded Cryptographic Key

Draft in the CWE catalog · 309 CVEs mapped

309
CVEs mapped
1
In KEV
7.3
Median CVSS
What it is

The product uses a hard-coded, unchangeable cryptographic key.

Recent examples
4.3cvss
CVE-2026-86241

liufee FeehiCMS Cookie Validation main-local.php hard-coded key

A weakness has been identified in liufee FeehiCMS up to 2.1.1. This impacts an unknown function of the file environments/prod/backend/config/main-local.php of the component Cookie Validation. This manipulation of the argument cookieValidationKey causes use of hard-coded cryptographic key . The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

MEDIUMno explanation yet
epss
7.8cvss
CVE-2026-80114

CVE-2026-80114 - HIGH Severity Vulnerability

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary physical memory writes by extracting an 8-byte key embedded as a hardcoded literal in the distributed binary and computing valid MD5 authentication tags for arbitrary IOCTL write requests. Attackers can additionally bypass a secondary validation gate by using the driver's own bit-clear IOCTL to clear a single bit in the gating instruction's displacement byte, causing all subsequent write requests to skip MAC verification, size checks, and Vendor ID checks entirely.

HIGHno explanation yet
0%
epss
9.1cvss
CVE-2026-75431

CVE-2026-75431 - CRITICAL Severity Vulnerability

PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.

CRITICALno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-321
Abstraction
Variant
Structure
Simple
Status
Draft
References (2)