Cyber Posture

CWE · MITRE source

CWE-259Use of Hard-coded Password

Abstraction: Variant · CVEs in our corpus: 187

The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

There are two main variations of a hard-coded password:

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (4)AI

Control Title Family Why it addresses this CWE
IA-5Authenticator ManagementIAChanging default authenticators prior to first use directly prevents use of hard-coded passwords.
PM-16Threat Awareness ProgramPMShared threat data frequently highlights products or deployments still using hard-coded passwords, enabling remediation that directly blocks credential-based attacks.
SA-21Developer ScreeningSABackground checks and authorization requirements decrease the probability that a developer will hard-code passwords for later unauthorized access.
SR-6Supplier Assessments and ReviewsSRReviews of supplier deliverables reduce the chance that hard-coded passwords are introduced into the system.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-73327.59.80.92112024-08-01
CVE-2023-52226.76.30.90242023-09-27
CVE-2025-577886.36.50.83122025-08-20
CVE-2025-87303.89.80.30212025-08-08
CVE-2023-26452.39.80.06242023-05-11
CVE-2025-11002.19.80.01852025-02-12
CVE-2016-93582.09.80.00542017-06-30
CVE-2017-60222.09.80.00532017-06-30
CVE-2015-39532.09.80.00252019-03-25
CVE-2014-54342.09.80.00252019-03-26
CVE-2020-120162.09.80.00212020-06-29
CVE-2020-120452.09.80.00282020-06-29
CVE-2020-120472.09.80.00282020-06-29
CVE-2021-274402.09.80.00272021-03-25
CVE-2019-108812.09.80.00482021-04-13
CVE-2021-227292.09.80.00352021-07-21
CVE-2021-384562.09.80.00222021-10-12
CVE-2021-346012.09.80.00412022-04-27
CVE-2017-200392.09.80.00402022-06-11
CVE-2022-302712.09.80.00202022-07-26
CVE-2022-221442.09.80.00382022-08-05
CVE-2022-416532.09.80.00272022-12-13
CVE-2022-454442.010.00.00572023-01-18
CVE-2024-280102.09.80.00402024-03-28
CVE-2024-274882.09.80.00442024-04-08