CWE-256
CWE-256 · 3 records · 1 with a public proof-of-concept
Records the NVD classes under CWE-256, highest CVSS first.
- HIGH 7.5CVE-2026-84884
IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST acces…
- HIGH 7.4CVE-2026-2380
On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may be stored on the local EOS device or recorded on remote accounting ser…
- UNSCOREDCVE-2026-104892public PoC
Plane is an open-source project management tool. Prior to 1.4.0, aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low privileges to steal user API keys and further escalate their privileges. This issue is fixed in 1.4.0.