Common Weakness Enumeration

    CWE Definition / CWE-921

    CWE-921: Storage of Sensitive Data in a Mechanism without Access Control

    The product stores sensitive information in a file system or device that does not have built-in access control.

    Published:22 Jun 2013
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-922: Insecure Storage of Sensitive Information