Common Weakness Enumeration

    CWE Definition / CWE-260

    CWE-260: Password in Configuration File

    The product stores a password in a configuration file that might be accessible to actors who do not know the password.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-522: Insufficiently Protected Credentials