Hard-coded Credentials vulnerabilities
CWE-798 · 12 tracked
Hard-coded Credentials (CWE-798) is a recognized software weakness class in the MITRE CWE catalog. The vulnerabilities below are all instances of this pattern.
How it’s exploited
How hard-coded credentials is exploited depends on the specific vulnerability, but every CVE in this class shares the same underlying flaw pattern — which is why the same class of mitigation applies across them.
How to prevent it
Recognizing the hard-coded credentials pattern lets you apply one class of fix across every affected component. Each CVE page below carries specific, version-level remediation.
Tracked hard-coded credentials vulnerabilities
12 CVEs in this class, each with severity, exploit status, EPSS, and remediation.
CVE-2026-61740CVE-2026-55579CVE-2026-49352CVE-2026-57147CVE-2026-57148CVE-2026-56266CVE-2026-48031CVE-2026-44825CVE-2026-47410CVE-2026-47255GHSA-8pqq-224h-x875GHSA-2qqc-p94c-hxwh
Frequently asked questions
- What is Hard-coded Credentials?
- Hard-coded Credentials (CWE-798) is a recognized software weakness class in the MITRE CWE catalog. The vulnerabilities below are all instances of this pattern.
- How is hard-coded credentials exploited?
- How hard-coded credentials is exploited depends on the specific vulnerability, but every CVE in this class shares the same underlying flaw pattern — which is why the same class of mitigation applies across them.
- How do you prevent hard-coded credentials?
- Recognizing the hard-coded credentials pattern lets you apply one class of fix across every affected component. Each CVE page below carries specific, version-level remediation.
- How many hard-coded credentials vulnerabilities are there?
- O3 tracks 12 vulnerabilities classified as CWE-798 (Hard-coded Credentials), each with severity, exploit status, EPSS exploitation probability, and remediation. The full list is below.