The product uses an environment variable to store unencrypted sensitive information.
Volume of CVEs assigned to CWE-526 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45370HIGH python-utcp is the python implementation of UTCP. Prior to 1.1.3, _prepare_environment() in cli_communication_protocol.py passes a full copy of os.environ to every CLI subprocess. | May 14, 2026 | 7.7 | 30 | NO | NO |
CVE-2026-49377MEDIUM In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters | May 29, 2026 | 4.3 | 23 | NO | NO |
CVE-2026-40153MEDIUM PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in shell_tools.py calls os.path.expandvars() on every command argument at line 64, man | Apr 9, 2026 | 6.5 | 23 | NO | NO |
CVE-2023-5720HIGH A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an | Nov 15, 2023 | 7.5 | 23 | NO | NO |
CVE-2025-36017MEDIUM IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obta | Dec 8, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-28381HIGH A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. | Jun 13, 2025 | 7.5 | 22 | NO | NO |
CVE-2023-43029HIGH IBM Storage Virtualize vSphere Remote Plug-in 1.0 and 1.1 could allow a remote user to obtain sensitive credential information after deployment. | Mar 21, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-12604MEDIUM Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App | Mar 10, 2025 | 6.5 | 21 | NO | NO |
CVE-2024-2700HIGH A vulnerability was found in the quarkus-core component. Quarkus captures local environment variables from the Quarkus namespace during the application's build, therefore, running | Apr 4, 2024 | 7.0 | 21 | NO | NO |
CVE-2025-27899MEDIUM IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 discloses sensitive information in an environment variable that could aid in further attacks against the system. | Feb 17, 2026 | 5.3 | 20 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.