CWE-798— Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.— MITRE CWE catalog
1,904 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-798page 2 of 39
- CVE-2023-1748CRITICALCVSS 9.3EG 10.02023-04-04
The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (…
- CVE-2018-5551CRITICALCVSS 9.0EG 10.02018-03-19
Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contain three credentials with known passwords: QDMaster, OTMaster, and sa.
- CVE-2014-9198HIGHCVSS v2 10.0EG 10.02015-01-27
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.
- CVE-2012-6428HIGHCVSS v2 10.0EG 10.02012-12-23
The Carlo Gavazzi EOS-Box stores hard-coded passwords in the PHP file of the device. By using the hard-coded passwords, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthoriz…
- CVE-2007-1063HIGHCVSS v2 10.0EG 10.02007-02-22
The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the device.
- CVE-2026-86464CRITICALCVSS 9.9EG 9.92026-09-08
In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. …
- CVE-2026-46386CRITICALCVSS 9.9EG 9.92026-06-26
OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :mar…
- CVE-2025-6950CRITICALCVSS 9.9EG 9.92025-10-17
An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs a hard-coded secret key to sign JSON Web Tokens (JWT) used for authentication. This insecure impleme…
- CVE-2023-39420CRITICALCVSS 9.9EG 9.92023-09-07
The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-en…
- CVE-2019-11898CRITICALCVSS 9.9EG 9.92019-09-12
Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with Bosch Access Professional Edition (APE) 3.8.
- CVE-2026-105278CRITICALCVSS 9.8EG 9.82026-10-09
The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An attacker with network access to the management interface can authenticate using this credential and gain full administ…
- CVE-2026-62252CRITICALCVSS 9.8EG 9.82026-10-07
Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (s…
- CVE-2026-61421CRITICALCVSS 9.8EG 9.82026-10-06
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization. An unauthenticated attacker with remote access could potentially exploit this vulnerability, lead…
- CVE-2026-105641CRITICALCVSS 9.8EG 9.82026-10-05
Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when o…
- CVE-2026-47116CRITICALCVSS 9.8EG 9.82026-09-22
LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account passwords are stored in /etc/shadow as weak hashes recoverable with dictionary-based cracking tools. The recovered credentials authentica…
- CVE-2026-76708CRITICALCVSS 9.8EG 9.82026-09-22
A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and system accounts. An unauthenticated remote attacker …
- CVE-2026-65113CRITICALCVSS 9.8EG 9.82026-09-22
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of s…
- CVE-2026-81440CRITICALCVSS 9.8EG 9.82026-09-17
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized …
- CVE-2026-92787CRITICALCVSS 9.8EG 9.82026-09-16
Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain tr…
- CVE-2026-37152CRITICALCVSS 9.8EG 9.82026-09-15
TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.
- CVE-2026-79396CRITICALCVSS 9.8EG 9.82026-09-11
Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowing…
- CVE-2026-71801CRITICALCVSS 9.8EG 9.82026-09-09
An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A rem…
- CVE-2026-85148CRITICALCVSS 9.8EG 9.82026-09-04
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
- CVE-2026-85146CRITICALCVSS 9.8EG 9.82026-09-04
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the applica…
- CVE-2026-85391CRITICALCVSS 9.8EG 9.82026-09-03
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary…
- CVE-2026-38577CRITICALCVSS 9.8EG 9.82026-08-31
Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
- CVE-2026-82448CRITICALCVSS 9.8EG 9.82026-08-29
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key …
- CVE-2021-43717CRITICALCVSS 9.8EG 9.82026-08-18
An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can access the projector using hard-coded authentication information and control the projector malicious…
- CVE-2026-74891CRITICALCVSS 9.8EG 9.82026-08-17
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default credentials to retrieve sensitive…
- CVE-2026-67614CRITICALCVSS 9.8EG 9.82026-08-13
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSoc…
- CVE-2026-73519CRITICALCVSS 9.8EG 9.82026-08-12
WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this valu…
- CVE-2026-69102CRITICALCVSS 9.8EG 9.82026-08-11
MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the pas…
- CVE-2025-63823CRITICALCVSS 9.8EG 9.82026-08-05
My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values.
- CVE-2026-65879CRITICALCVSS 9.8EG 9.82026-07-27
Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.
- CVE-2026-8983CRITICALCVSS 9.8EG 9.82026-07-21
Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functi…
- CVE-2026-13446CRITICALCVSS 9.8EG 9.82026-07-17
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal dat…
- CVE-2026-55579CRITICALCVSS 9.8EG 9.82026-07-16
Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash stored at pheditor.php:11). There is no mechanism to force a…
- CVE-2026-37270CRITICALCVSS 9.8EG 9.82026-07-07
Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware.
- CVE-2026-14807CRITICALCVSS 9.8EG 9.82026-07-06
ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code and obtain the database account and password.
- CVE-2026-49352CRITICALCVSS 9.8EG 9.82026-07-02
9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/route.js, src/middleware.js, and later src/lib/auth/dashboardSession…
- CVE-2026-31928CRITICALCVSS 9.8EG 9.82026-06-26
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.
- CVE-2026-56265CRITICALCVSS 9.8EG 9.82026-06-21
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any user, bypassing aut…
- CVE-2026-47846CRITICALCVSS 9.8EG 9.82026-06-18
Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrator account is configured via the CASSANDRA_USER environment variable, the container initialization script creates the n…
- CVE-2026-57147CRITICALCVSS 9.8EG 9.82026-06-18
PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run when …
- CVE-2026-57148CRITICALCVSS 9.8EG 9.82026-06-18
PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup and token-issuance gu…
- CVE-2026-9260CRITICALCVSS 9.8EG 9.82026-06-16
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
- CVE-2026-50083CRITICALCVSS 9.8EG 9.82026-06-12
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N…
- CVE-2026-10557CRITICALCVSS 9.8EG 9.82026-06-12
The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are readily extractable via APK decompilation.…
- CVE-2026-11849CRITICALCVSS 9.8EG 9.82026-06-12
The iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing unauthenticated remote attackers to exploit hard-coded credentials to gain administrative privileges on the database.
- CVE-2026-11414CRITICALCVSS 9.8EG 9.82026-06-05
A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical across all installations, an unauthenticated network attacker who can reach the server can for…
Map vulnerabilities like CWE-798 to your infrastructure
EchelonGraph correlates every CVE — across CWE-798 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →