CWE-526: Cleartext Storage of Sensitive Information in an Environment Variable

ID CWE-526
Abstraction Variant
Structure Simple
Status Incomplete
Number of CVEs 5
The product uses an environment variable to store unencrypted sensitive information.

Information stored in an environment variable can be accessible by other processes with the execution context, including child processes that dependencies are executed in, or serverless functions in cloud environments. An environment variable's contents can also be inserted into messages, headers, log files, or other outputs. Often these other dependencies have no need to use the environment variable in question. A weakness that discloses environment variables could expose this information.

Modes of Introduction

Phase Note
Architecture and Design


View Weakness
# ID View Status # ID Name Abstraction Structure Status
CWE-1000 Research Concepts Draft CWE-312 Cleartext Storage of Sensitive Information Base Simple Draft
CWE-1000 Research Concepts Draft CWE-214 Invocation of Process Using Visible Sensitive Information Base Simple Incomplete

CVEs Published

CVSS Severity

CVSS Severity - By Year

CVSS Base Score

# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date