CWE-312— Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.— MITRE CWE catalog
867 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 17 of 18
- CVE-2026-28758MEDIUMCVSS 4.4EG 4.42026-05-13
When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return the ssh-password parameter in cleartext in the iControl REST response and is also logged in the audit log. This may a…
- CVE-2026-31848CRITICALCVSS 9.8EG 9.82026-03-23
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is reversible and lacks integrit…
- CVE-2026-3221MEDIUMCVSS 4.9EG 4.92026-02-25
Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.
- CVE-2026-3277MEDIUMCVSS 6.5EG 6.52026-02-27
The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows an attacker with read access to that file…
- CVE-2026-32842MEDIUMCVSS 6.5EG 6.52026-03-17
Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows attackers to obtain administrator credentials by accessing configuration backup files. Attackers can download the config.b…
- CVE-2026-33003MEDIUMCVSS 4.3EG 4.32026-03-18
Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file …
- CVE-2026-33026CRITICALCVSS 9.1EG 9.12026-03-30
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This …
- CVE-2026-33512HIGHCVSS 7.5EG 7.52026-03-23
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptString` action without any authentication. Anyone can submit ciphertext and receive plaintext. Ciphertext is issued public…
- CVE-2026-33867HIGHCVSS 7.5EG 7.52026-03-27
WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to password-protect individual videos. The video password is stored in the database in plaintext — no hashing, salting, or e…
- CVE-2026-34214MEDIUMCVSS 6.5EG 6.52026-03-31
Trino is a distributed SQL query engine for big data analytics. From version 439 to before version 480, Iceberg connector REST catalog static credentials (access key) or vended credentials (temporary access key) are accessible to users tha…
- CVE-2026-34490MEDIUMCVSS 5.5EG 5.52026-07-31
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: b…
- CVE-2026-34833HIGHCVSS 7.5EG 7.52026-04-02
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/session endpoint previously included the user's plaintext password in the JSON response. This exposed credentials to brows…
- CVE-2026-35644MEDIUMCVSS 6.5EG 6.52026-04-09
OpenClaw before 2026.3.22 contains an information disclosure vulnerability that allows attackers with operator.read scope to expose credentials embedded in channel baseUrl and httpUrl fields. Attackers can access gateway snapshots via conf…
- CVE-2026-36176HIGHCVSS 7.1EG 7.12026-06-04
GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active tokens to perform unauthorized operations vi…
- CVE-2026-38571MEDIUMCVSS 4.6EG 4.62026-06-26
Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, in the unauthenticated UART debug console of the Tenda N300 F3 (V603) allow a physically proximate attacker to obtain s…
- CVE-2026-39943MEDIUMCVSS 6.5EG 6.52026-04-09
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revision records (in directus_revisions) whenever items are created or updated. Due to the revision snapshot code not consis…
- CVE-2026-41385MEDIUMCVSS 6.5EG 6.52026-04-28
OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get method calls that bypass redaction mechanisms. Attackers can retrieve unredacted configuration data to obtain plaintext s…
- CVE-2026-41520HIGHCVSS 7.9EG 7.92026-05-08
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.18.9, and 1.19.3, the output of cilium-bugtool can contain sensitive data when the tool is run against Cilium deploymen…
- CVE-2026-42151HIGHCVSS 7.5EG 7.52026-05-04
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of S…
- CVE-2026-42408MEDIUMCVSS 4.4EG 4.42026-05-13
When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a highly privileged authenticated attacker to view sensitive information. Note: Software versions which have reached End o…
- CVE-2026-4346MEDIUMCVSS 6.8EG 6.82026-03-26
The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of the device’s flash memory while the serial interface remains enabled and protected by weak authentication. An attac…
- CVE-2026-43824HIGHCVSS 7.7EG 7.72026-05-02
In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
- CVE-2026-4387LOWCVSS 2.0EG 2.02026-05-29
StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users…
- CVE-2026-43942MEDIUMCVSS 5.5EG 6.52026-05-08
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, the getConstants() IPC handler in src/app/lib/ipc-sync.js serialises the entire process.env object and sends it to the …
- CVE-2026-43992CRITICALCVSS 9.8EG 9.82026-05-12
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate_contract, upload_wasm, ibc_transfer, etc.) accepted 'mnemonic: string' as an explicit too…
- CVE-2026-45040MEDIUMCVSS 5.3EG 5.32026-05-28
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive information leakage in log outputs. When the server is run with RUST_LOG=debug sensitive credentials including SessionToken (…
- CVE-2026-45362LOWCVSS 3.2EG 3.22026-05-12
Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.
- CVE-2026-46622HIGHCVSS 8.1EG 8.12026-06-11
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any attacker who obtains read access to the…
- CVE-2026-47702CRITICALCVSS 9.1EG 9.12026-08-11
TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings. An attacker who gains read access to the database (e.g., vi…
- CVE-2026-50267MEDIUMCVSS 4.7EG 4.72026-06-17
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Abstractions 4.0.0 through 4.1.0, when MySQL or PostgreSQL service bindings from `VCAP_S…
- CVE-2026-5224MEDIUMCVSS 5.7EG 5.72026-08-18
Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve Embedded Sensitive Data. This issue affects Cryptosim: before 3.1.0.229.
- CVE-2026-5531MEDIUMCVSS 5.3EG 5.32026-04-05
A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. The manipulation leads to cleartext storag…
- CVE-2026-55885MEDIUMCVSS 6.8EG 6.82026-06-18
Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, including user/accounts/admin.yaml with the administrator pas…
- CVE-2026-55985MEDIUMCVSS 4.3EG 4.32026-07-24
The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboar…
- CVE-2026-55997HIGHCVSS 8.8EG 8.82026-08-05
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Ranc…
- CVE-2026-57287MEDIUMCVSS 4.3EG 4.32026-06-24
Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations, allowing attackers with Extended Read permission to view enc…
- CVE-2026-59244MEDIUMCVSS 6.5EG 6.52026-08-12
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a t…
- CVE-2026-59327MEDIUMCVSS 4.4EG 4.42026-07-30
Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attribute on the "Spring Boot DevTools Client" launch configuration. Eclipse persists launch configuration attributes …
- CVE-2026-59657HIGHCVSS 7.5EG 7.52026-08-21
Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. This issue affects Apache CloudStack: from 4.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommen…
- CVE-2026-61928MEDIUMCVSS 5.5EG 5.52026-08-11
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
- CVE-2026-6332HIGHCVSS 7.5EG 7.52026-05-14
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized atta…
- CVE-2026-6553HIGHCVSS 7.5EG 7.52026-04-21
Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.
- CVE-2026-65599MEDIUMCVSS 6.5EG 6.52026-07-22
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key was mistakenly placed in the JWT header's kid field (intended only fo…
- CVE-2026-6598MEDIUMCVSS 4.3EG 4.32026-04-20
A security vulnerability has been detected in langflow-ai langflow up to 1.8.3. The affected element is the function create_project/encrypt_auth_settings of the file src/backend/base/Langflow/api/v1/projects.py of the component Project Cre…
- CVE-2026-66016MEDIUMCVSS 6.7EG 6.72026-08-12
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
- CVE-2026-66781MEDIUMCVSS 6.5EG 6.52026-08-18
A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communica…
- CVE-2026-66782HIGHCVSS 7.8EG 7.82026-08-18
A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker service account (SA) bearer token within the Submariner Custom Resource (CR) specification. An attacker with access to the clust…
- CVE-2026-6796MEDIUMCVSS 4.3EG 4.32026-04-21
A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file core/src/main/java/com/publiccms/controller/admin/LoginAdminController.java of the component Failed Login Handler. This ma…
- CVE-2026-68970MEDIUMCVSS 6.5EG 6.52026-08-12
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserializ…
- CVE-2026-7163MEDIUMCVSS 5.5EG 6.12026-04-30
A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative …
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →