cwe-798
Safeguard articles tagged "cwe-798" — guides, analysis, and best practices for software supply chain and application security.
11 articles
CVE-2020-8657: EyesOfNetwork Use of Hard-Coded Credentials Vulnerability
CVE-2020-8657 affects EyesOfNetwork EyesOfNetwork and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2022-26138: Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
CVE-2022-26138 affects Atlassian Confluence and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-07-29.
CVE-2024-3272: D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
CVE-2024-3272 affects D-Link Multiple NAS Devices and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-04-11.
CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability
CVE-2024-28987 affects SolarWinds Web Help Desk and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-10-15.
CVE-2021-44207: Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability
CVE-2021-44207 affects Acclaim Systems USAHERDS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-12-23.
CVE-2019-6693: Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability
CVE-2019-6693 affects Fortinet FortiOS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-06-25.
CVE-2025-14611: Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
CVE-2025-14611 affects Gladinet CentreStack and Triofox and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-12-15.
CVE-2026-22769: Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
CVE-2026-22769 affects Dell RecoverPoint for Virtual Machines (RP4VMs) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-18.
Uber (2016): Hardcoded Credentials in a Private Repository
A factual retrospective on the 2016 Uber breach, where attackers used credentials found in a private GitHub repository to access an AWS account holding rider and driver data, and how it was later concealed.
Hardcoded credentials vulnerabilities explained
Hardcoded credentials (CWE-798) have caused real breaches at Uber, Toyota, and Mercedes-Benz. Here's how they happen, how common they are, and how to fix them.
What Are Hardcoded Credentials
Hardcoded credentials are secrets baked into code instead of a vault. Toyota, Uber, and Samsung breaches show why that risk never expires on its own.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.