Common Weakness Enumeration

    CWE Definition / CWE-259

    CWE-259: Use of Hard-coded Password

    The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-798: Use of Hard-coded Credentials

    CWE-798: Use of Hard-coded Credentials

    CWE-798: Use of Hard-coded Credentials

    CWE-321: Use of Hard-coded Cryptographic Key

    CWE-257: Storing Passwords in a Recoverable Format