CWE-522Class2 in KEV

Insufficiently Protected Credentials

Incomplete in the CWE catalog · 527 CVEs mapped

527
CVEs mapped
2
In KEV
6.8
Median CVSS
What it is

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Recent examples
6.5cvss
CVE-2026-86175

CVE-2026-86175 - MEDIUM Severity Vulnerability

NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backends through API endpoints, gaining unauthorized access to external repositories and storage buckets.

MEDIUMno explanation yet
0%
epss
none
CVE-2026-53603

CVE-2026-53603 - UNKNOWN Severity Vulnerability

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32-byte random hex value sent directly in a cookie and valid for 24 hours. Anyone who can read the database (backup, snapshot, file copy, or SQL-level disclosure) obtains every active session token and can hijack operator sessions directly, with no further authentication. This issue has been patched in version 0.3.8.

no explanation yet
0%
epss
6.5cvss
CVE-2026-85700

CVE-2026-85700 - MEDIUM Severity Vulnerability

Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authenticated user to read admin-defined API keys. Attackers with basic authentication can call GET /tool/{tool_id} or GET /tool endpoints to retrieve plaintext authorization headers and third-party API credentials, then use them to directly access upstream APIs.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-522
Abstraction
Class
Structure
Simple
Status
Incomplete
References (1)