CWE-1391— Use of Weak Credentials
The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.— MITRE CWE catalog
57 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1391page 2 of 2
- CVE-2026-45363CRITICALCVSS 9.1EG 9.12026-05-18
ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', payload…
- CVE-2026-47325MEDIUMCVSS 6.9EG 6.92026-06-03
ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's passwords solely from the user’s date of birth (e.g., 12072000 for 12 July 2000). The application does not require or prompt…
- CVE-2026-49852HIGHCVSS 8.7EG 8.72026-07-02
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-forged HMAC-signed tokens when the caller-supplied verification…
- CVE-2026-57473MEDIUMCVSS 5.8EG 5.82026-06-26
A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of brute-force cracking the credentials. This issue could allow attackers on the same local net…
- CVE-2026-66408MEDIUMCVSS 4.6EG 4.62026-08-10
The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected product may allow to obtain the password of the root account.
- CVE-2026-66409MEDIUMCVSS 5.3EG 5.32026-08-10
DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to connect to the access point of an affected robot.
- CVE-2026-8076CRITICALCVSS 9.3EG 9.32026-05-08
Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs for user authentication. The system supports the use of PIN-based credentials, maintaining compatibility wit…
Map vulnerabilities like CWE-1391 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1391 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →