Cyber Posture

CWE · MITRE source

CWE-260Password in Configuration File

Abstraction: Base · CVEs in our corpus: 24

The product stores a password in a configuration file that might be accessible to actors who do not know the password.

This can result in compromise of the system for which the password is used. An attacker could gain access to this file and learn the stored password or worse yet, change the password to one of their choosing.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (0)AI

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2017-79256.89.80.80412017-05-06
CVE-2023-341282.09.80.00262023-07-13
CVE-2025-577542.09.80.00102025-08-21
CVE-2025-250221.99.60.00122025-06-03
CVE-2025-65131.99.30.00092025-06-23
CVE-2017-79231.88.80.00552017-05-06
CVE-2019-37801.88.80.00382019-03-08
CVE-2025-321111.88.70.00182025-04-04
CVE-2021-350331.67.80.00112021-11-23
CVE-2025-330931.57.50.00222025-05-07
CVE-2023-537701.57.50.00262025-12-09
CVE-2019-254651.57.50.00402026-03-11
CVE-2025-331191.36.50.00032025-11-12
CVE-2016-70431.25.90.00232019-05-15
CVE-2020-57211.15.50.00102020-04-15
CVE-2024-456731.15.50.00032025-02-21
CVE-2025-515401.15.30.00062025-08-19
CVE-2025-360021.15.50.00012025-10-16
CVE-2025-361001.05.10.00012025-09-07
CVE-2024-498170.94.40.00042024-12-17
CVE-2025-151510.73.70.00052025-12-28
CVE-2023-27900.52.30.00032023-05-18
CVE-2014-54000.00.00.00062015-04-03
CVE-2023-537390.00.00.00322025-12-09