# CWE-312: Cleartext Storage of Sensitive Information

**KEV-linked**

> As of 2026-10-10, CWE-312 (Cleartext Storage of Sensitive Information) underlies 4 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 18 tracked threats.

**Last updated:** 2026-10-10

## What is CWE-312?

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

CWE-312 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Technology: Cloud Computing; Technology: ICS/OT; Technology: Mobile.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/312.html) (CWE-312 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Confidentiality** — Read Application Data. An attacker with access to the system could read sensitive information stored in cleartext (i.e., unencrypted). Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.

_Source: MITRE CWE, common consequences._

## How CWE-312 is exploited in the wild

Threadlinqs maps 4 CVEs to CWE-312, published between 2023-04-19 and 2026-08-05. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 2 high, 1 medium. The highest EPSS score in the set is 3.4% (CVE-2023-22894), the modelled probability of exploitation in the next 30 days. 18 tracked threats reference CWE-312 directly or through a CVE it covers; the most recent is “Chinese Government-linked Actors Enabled by Integrity Technology Group Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data (CISA AA26-281A)” (2026-10-08). Affected products concentrate in Cisco (1), Microsoft (1), StrongDM (1).

## Vulnerabilities (CVEs)

All 4 CVEs mapped to CWE-312, CISA KEV first, then by CVSS score.

- [CVE-2023-22894](https://intel.threadlinqs.com/cve/CVE-2023-22894) — CISA KEV · CVSS 7.2 high · EPSS 3.4% · published 2023-04-19
- [CVE-2026-20312](https://intel.threadlinqs.com/cve/CVE-2026-20312) — CVSS 8.8 high · EPSS 0.3% · published 2026-08-05
- [CVE-2026-23655](https://intel.threadlinqs.com/cve/CVE-2026-23655) — CVSS 6.5 medium · EPSS 1.0% · published 2026-02-10
- [CVE-2026-4387](https://intel.threadlinqs.com/cve/CVE-2026-4387) — EPSS 0.1% · published 2026-05-29

## Affected vendors

- [Cisco](https://intel.threadlinqs.com/vendors/cisco) — 1 CVE
- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 1 CVE
- **StrongDM** — 1 CVE

## Threat activity

18 tracked threats cite CWE-312:

- [Chinese Government-linked Actors Enabled by Integrity Technology Group Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data (CISA AA26-281A)](https://intel.threadlinqs.com/threat/TL-2026-3054) — HIGH · 2026-10-08
- [Personal GitHub Repositories Are a Major Blind Spot for Corporate Secret Leaks (Wiz Research)](https://intel.threadlinqs.com/threat/TL-2026-2009) — MEDIUM · 2026-08-13
- [Multiple Critical Vulnerabilities in Cisco Catalyst SD-WAN Software (CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313)](https://intel.threadlinqs.com/threat/TL-2026-1905) — CRITICAL · 2026-08-06
- [Pass-ta-Key Attacks Let Malware Hijack Google Password Manager Synchronized Passkeys (Chrome on Windows)](https://intel.threadlinqs.com/threat/TL-2026-1886) — HIGH · 2026-08-05
- [Microsoft shortens NuGet.org API key lifetimes to 30 days for supply-chain hardening (effective Aug 17, 2026)](https://intel.threadlinqs.com/threat/TL-2026-1876) — MEDIUM · 2026-08-04
- [Pass-ta-key: Novel Attack Surface in Google Password Manager Synced Passkey Authentication](https://intel.threadlinqs.com/threat/TL-2026-1842) — CRITICAL · 2026-08-03
- [Dolphin X Windows Infostealer Adds AI-Driven Victim Profiling and Polymorphic Panel](https://intel.threadlinqs.com/threat/TL-2026-1695) — HIGH · 2026-07-22
- [CISA, NSA, JPCERT/CC, NCSC-NL and NCSC-UK Publish Joint Guidance: Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1419) — INFO · 2026-07-16
- [JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos (CVE-2021-29441)](https://intel.threadlinqs.com/threat/TL-2026-1083) — CRITICAL · 2026-07-02
- [Alleged Huntress Insider Leaked Law Enforcement Communications to DevMan Ransomware Operation (DragonForce/Conti Lineage)](https://intel.threadlinqs.com/threat/TL-2026-0970) — HIGH · 2026-06-28
- [Claude Code MCP Traffic Hijack via Malicious npm postinstall — ~/.claude.json Tampering Proxies MCP Endpoints to Steal Persistent OAuth Bearer Tokens (Mitiga Labs PoC)](https://intel.threadlinqs.com/threat/TL-2026-0712) — HIGH · 2026-06-08
- [StrongDM Desktop CVE-2026-4387 — Plaintext Session State (JWT + Asymmetric Keypair) Enables Credential-less Cross-Host Session Hijack](https://intel.threadlinqs.com/threat/TL-2026-0654) — HIGH · 2026-06-02
- [SolyxImmortal Python Infostealer — Chromium/Firefox Credential & Cookie Theft, Keylogging, Discord Webhook Exfiltration (Turkish-Speaking Actor)](https://intel.threadlinqs.com/threat/TL-2026-0659) — HIGH · 2026-06-02
- [Apple iOS/iPadOS Notification Services Data Retention Zero-Day (CVE-2026-28950) — Exploited In-The-Wild for Forensic Extraction of Signal Messages](https://intel.threadlinqs.com/threat/TL-2026-0413) — HIGH · 2026-04-23
- [Storm Infostealer (v0.0.2.0 Gunnar): Server-Side Browser Decryption Bypasses Chrome App-Bound Encryption and Hijacks MFA-Protected SaaS Sessions](https://intel.threadlinqs.com/threat/TL-2026-0355) — HIGH · 2026-04-13
- [February 2026 Patch Tuesday: Six Zero-Days Among 59 CVEs](https://intel.threadlinqs.com/threat/TL-2026-0064) — CRITICAL · 2026-02-12
- [February 2026 Patch Tuesday: Six Zero-Days Among 59 CVEs — CrowdStrike-Discovered RDP EoP Exploited Since December 2025](https://intel.threadlinqs.com/threat/TL-2026-0074) — CRITICAL · 2026-02-12
- [Panera Bread Data Breach - 5.1 Million Accounts Exposed](https://intel.threadlinqs.com/threat/TL-2026-0031) — MEDIUM · 2026-02-02

## Mitigations

- **Implementation, System Configuration, Operation**: When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to encrypt the data at rest. [REF-1297] [REF-1299] [REF-1301]
- **Implementation, System Configuration, Operation**: In some systems/environments such as cloud, the use of "double encryption" (at both the software and hardware layer) might be required, and the developer might be solely responsible for both layers, instead of shared responsibility with the administrator of the broader system/environment.

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Automated Static Analysis** (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-311 Missing Encryption of Sensitive Data](https://intel.threadlinqs.com/cwe/CWE-311)
- CWE-922 Insecure Storage of Sensitive Information

Canonical: https://intel.threadlinqs.com/cwe/CWE-312
Source definition: https://cwe.mitre.org/data/definitions/312.html
Detection rules and IOCs for threats exploiting CWE-312 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
