Common Weakness Enumeration
CWE Definition / CWE-1266
CWE-1266: Improper Scrubbing of Sensitive Data from Decommissioned Device
The product does not properly provide a capability for the product administrator to remove sensitive data at the time the product is decommissioned. A scrubbing capability could be missing, insufficient, or incorrect.
Published:28 May 2020
Organization:MITRE
Modified:11 Dec 2025
Related Weakness
CWE-404: Improper Resource Shutdown or Release
