← Back to feed Search feed

CWE-798 Hardcoded Credentials vulnerabilities

28 CVEs — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-57147PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public CRITICAL9.854%ileNVD2026-09-15
CVE-2026-57148PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the pCRITICAL9.830%ileNVD2026-09-15
CVE-2026-37152TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.CRITICAL9.840%ileNVD2026-09-15
CVE-2026-78225A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOSCRITICAL9.535%ileNVD2026-09-15
CVE-2026-66890The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTCRITICAL9.410%ileNVD2026-09-15
CVE-2026-81855A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of WärCRITICAL9.341%ileNVD2026-09-15
CVE-2026-92787Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypasCRITICAL9.331%ileNVD2026-09-16
CVE-2026-54767WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.phpCRITICAL9.136%ileNVD2026-09-17
CVE-2026-28326SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. HIGH8.845%ileNVD2026-09-17
CVE-2026-84034IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore HIGH8.8NVD2026-09-18
CVE-2026-90946DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSoHIGH8.746%ileNVD2026-09-14
CVE-2026-68950The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providiHIGH8.713%ileNVD2026-09-15
CVE-2026-86520Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active HIGH8.7NVD2026-09-18
CVE-2026-86689Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active HIGH8.2NVD2026-09-18
CVE-2026-16141OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force thHIGH8.133%ileNVD2026-09-15
CVE-2026-81440Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerabilityHIGH7.324%ileNVD2026-09-17
CVE-2026-90940novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpMEDIUM6.924%ileNVD2026-09-14
CVE-2026-77960Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active MEDIUM6.9NVD2026-09-18
CVE-2026-54147http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvidMEDIUM6.5NVD2026-09-18
CVE-2026-63406AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetMEDIUM5.9NVD2026-09-18
CVE-2026-90509A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspecMEDIUM5.522%ileNVD2026-09-13
CVE-2026-92579In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without MEDIUM5.35%ileNVD2026-09-16
CVE-2026-87965The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appoiMEDIUM4.84%ileNVD2026-09-18
CVE-2026-78427The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one ofMEDIUM4.330%ileNVD2026-09-17
CVE-2026-79551Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key.UNKNOWN18%ileNVD2026-09-15
CVE-2026-89905In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Move arena register slot below TCC UNKNOWN9%ileNVD2026-09-16
OSS-20260912-1Local Privilege Escalation (LPE) in FolkPatch due to Hardcoded Default SuperKeyUNKNOWNOSS-Security2026-09-12
FG-IR-26-129Hardcoded Encryption Key Used for VPN Saved PasswordsUNKNOWNFortinet2026-05-12