Common Weakness Enumeration

    CWE Definition / CWE-522

    CWE-522: Insufficiently Protected Credentials

    The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-1390: Weak Authentication

    CWE-287: Improper Authentication

    CWE-668: Exposure of Resource to Wrong Sphere