CWE-327Class

Use of a Broken or Risky Cryptographic Algorithm

Draft in the CWE catalog · 343 CVEs mapped

343
CVEs mapped
6.0
Median CVSS
What it is

The product uses a broken or risky cryptographic algorithm or protocol.

Recent examples
4.4cvss
CVE-2026-16693

CVE-2026-16693 - MEDIUM Severity Vulnerability

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys.

MEDIUMno explanation yet
0%
epss
6.2cvss
CVE-2026-81859

CVE-2026-81859 - MEDIUM Severity Vulnerability

CP4BA - IBM Enterprise Records could allow a local attacker to obtain sensitive information due to the use of a broken or risky cryptographic algorithm.

MEDIUMno explanation yet
0%
epss
9.8cvss
CVE-2026-76133

CVE-2026-76133 - CRITICAL Severity Vulnerability

The affected Ebyte product uses a deprecated hashing algorithm in an authentication-related operation. Under conditions where an attacker can manipulate or predict the authentication exchange, the weak construction may reduce the assurance provided by the authentication mechanism and facilitate unauthorized access.

CRITICALno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-327
Abstraction
Class
Structure
Simple
Status
Draft
References (13)