Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1392
Weakness type CWE-1392 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 29 | 28 | 0 |
Monthly trend
▂▁▁▂▁▄▅▆▂█▂
2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 4 · 2026-06 5 · 2026-07 7 · 2026-08 1 · 2026-09 9 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-58453 | 9.3 | 78.9 | — | JAIOTlink C492A-W6 4.8.30.57701411 Hard-coded Credentials via anyka_ipc |
| CVE-2026-41939 | 9.3 | 64.2 | — | Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly |
| CVE-2026-58466 | 9.3 | 55.2 | — | AutoBangumi < 3.2.8 - Hard-coded Default Credentials via add_default_user() |
| CVE-2026-68503 | 9.8 | 53.5 | — | LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 Dashboard |
| CVE-2026-31837 | 8.7 | 50.5 | — | Istio JWKS resolver to prevent private key material from being exposed when JWKS fetch … |
| CVE-2026-78573 | 9.8 | 45.5 | — | IBM ContextForge MCP Gateway is affected by use of default credentials |
| CVE-2026-86464 | 9.9 | 43.8 | — | — |
| CVE-2026-90940 | 6.9 | 43.8 | — | novel-plus through 5.3.3 Default Cache Management Password in the Front Portal |
| CVE-2026-44761 | 9.1 | 40.5 | — | Insecure Sample Credentials in SAP Commerce Cloud |
| CVE-2026-76155 | 9.3 | 40.2 | — | Datiphy Data Management Center - Use of Default Credentials |
| CVE-2026-46386 | 9.9 | 40.0 | — | OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default… |
| CVE-2026-45039 | 9.8 | 39.4 | — | RustFS: Internode RPC HMAC secret falls back to public default credential, enabling pee… |
| CVE-2026-90498 | 5.5 | 38.6 | — | lenve vhr vhr.sql default credentials |
| CVE-2026-3144 | 9.8 | 33.2 | — | IBM API Connect Default Credentials |
| CVE-2026-9844 | 8.8 | 32.5 | — | Vulnerability in navify® Digital Pathology |
| CVE-2018-25147 | 9.3 | 30.6 | — | Microhard Systems IPn4G 1.1.0 Default Credentials Authentication Bypass |
| CVE-2026-42941 | 8.7 | 25.5 | — | MacGregor Voyage Data Recorder (VDR) G4e Use of Default Credentials |
| CVE-2026-97064 | 9.3 | 20.8 | — | X-SpringBoot through 6.0 Authentication Bypass via Static Master Code |
| CVE-2026-90456 | 9.2 | 17.8 | — | Use of default credentials in Malcolm |
| CVE-2025-36221 | 7.5 | 17.3 | — | Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops. |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ibm | 4 |
| cisa | 2 |
| dell | 2 |
| 201206030 | 1 |
| andritz | 1 |
| brickcom | 1 |
| care everywhere | 1 |
| danelec | 1 |
| datiphy | 1 |
| eclipse foundation | 1 |
| estrellaxd | 1 |
| grisuno | 1 |
| innotim software, telecommunications and consultancy trade ltd. co | 1 |
| istio | 1 |
| jaiotlink | 1 |