Threats Tagged 'cwe-522'
View all threats tagged with 'cwe-522'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-522'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-21766: CWE-522 Insufficiently Protected Credentials in HCLSoftware HCL Digital Experience and Digital Experience ComposeCVE-2026-21766 0 The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs. This only affects applications using the default login portlet. Join the discussion | CVE Database V5 | 08/05/2026, 20:11:19 UTC Added: 08/05/2026, 20:26:48 UTC |
CVE-2026-52855: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in pterodactyl wingsCVE-2026-52855 0 Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, and {{config.docker.registries}} from the full daemon configuration. This issue is fixed in version 1.12.3. Join the discussion | CVE Database V5 | 07/31/2026, 16:16:42 UTC Added: 07/31/2026, 19:28:14 UTC |
CVE-2026-17349: CWE-639 Authorization Bypass Through User-Controlled Key in pgadmin.org pgAdmin 4CVE-2026-17349 0 /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, shared, shared_username, and the stored credential fields password, save_password, and tunnel_password. When a non-owner triggered an adhoc connect against another user's (in practice, typically an administrator's) shared server, the clone inherited that user's ownership, shared flag, and stored database credentials verbatim. pgAdmin persisted this cross-tenant, credential-bearing server row before the connection was even attempted, so it survived even when the connection subsequently failed. The non-owner could then open the newly-owned clone and pgAdmin would connect using the source user's stored database password on the non-owner's behalf, granting the non-owner use of database credentials -- and whatever database privileges they confer -- that were never their own. Fix forces the cloned adhoc record's ownership fields (user_id, shared, shared_username) and stored credential fields (password, save_password, tunnel_password) to belong to the calling user and be cleared/private before committing, regardless of the source server's ownership, sharing state, or stored credentials. A regression test asserts that an adhoc connect triggered by a non-owner against another user's shared server persists a row owned by the caller, not shared, and without the source's stored credentials. This issue affects pgAdmin 4: from 9.0 before 9.17. Join the discussion | CVE Database V5 | 07/31/2026, 15:59:47 UTC Added: 07/31/2026, 19:28:14 UTC |
CVE-2026-56570: CWE-522 Insufficiently Protected Credentials in HCL Software HCL iControlCVE-2026-56570 0 HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions. Join the discussion | CVE Database V5 | 07/31/2026, 14:59:02 UTC Added: 07/31/2026, 15:34:06 UTC |
CVE-2026-67427: CWE-522: Insufficiently Protected Credentials in flytohub flyto-coreCVE-2026-67427 0 Flytohub flyto-core versions prior to 2.26.6 contain a vulnerability where the workflow engine variable resolver expands environment variables without an allowlist or capability policy check. This allows workflow parameters to bypass default denylist policies and potentially exfiltrate secrets through allowed modules. The issue is fixed in version 2.26.6. Join the discussion | CVE Database V5 | 07/29/2026, 18:45:47 UTC Added: 07/29/2026, 18:52:44 UTC |
CVE-2026-67426: CWE-306: Missing Authentication for Critical Function in flytohub flyto-coreCVE-2026-67426 0 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes unauthenticated POST /run on 0.0.0.0:8344 and uses client-supplied callback_url for an outbound POST with X-Internal-Key: $FLYTO_RUNNER_SECRET while bypassing target_allowed, allowing unauthenticated SSRF and runner secret exfiltration. This issue is fixed in version 2.26.7. Join the discussion | CVE Database V5 | 07/29/2026, 18:43:26 UTC Added: 07/29/2026, 18:52:44 UTC |
CVE-2026-67425: CWE-201: Insertion of Sensitive Information Into Sent Data in flytohub flyto-coreCVE-2026-67425 0 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends them in the Authorization: Bearer header to caller-controlled base_url, allowing an attacker to receive the operator's key on a public host that passes the SSRF guard. This issue is fixed in version 2.26.6. Join the discussion | CVE Database V5 | 07/29/2026, 18:35:01 UTC Added: 07/29/2026, 18:52:44 UTC |
CVE-2026-54660: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in acacode swagger-typescript-apiCVE-2026-54660 0 A vulnerability in swagger-typescript-api prior to version 13.12.2 allows exposure of sensitive bearer tokens. The issue occurs because the authorization token is forwarded to every URL fetched when resolving external references in OpenAPI specifications. This can lead to an attacker-controlled OpenAPI spec exfiltrating the developer or CI bearer token to a cross-origin endpoint. The vulnerability is fixed in version 13.12.2. Join the discussion | CVE Database V5 | 07/29/2026, 14:21:34 UTC Added: 07/29/2026, 14:52:48 UTC |
CVE-2026-17569: CWE-522 Insufficiently Protected Credentials in Devolutions ServerCVE-2026-17569 0 Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier Join the discussion | CVE Database V5 | 07/27/2026, 17:37:19 UTC Added: 07/27/2026, 18:22:59 UTC |
CVE-2026-54422: CWE-522 Insufficiently Protected Credentials in OpenStack Ironic Python AgentCVE-2026-54422 0 In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it. Join the discussion | CVE Database V5 | 07/24/2026, 03:42:26 UTC Added: 07/24/2026, 04:52:45 UTC |
Showing 1 to 10 of 20 results