Common Weakness Enumeration
CWE Definition / CWE-260
CWE-260: Password in Configuration File
The product stores a password in a configuration file that might be accessible to actors who do not know the password.
Published:19 Jul 2006
Organization:MITRE
Modified:11 Dec 2025
Related Weakness
CWE-522: Insufficiently Protected Credentials
