CWE · MITRE source
CWE-326Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.
Last updated: 20 August 2026 13:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: mostly · 6 mapping(s) from 5 framework(s): CAPEC 2 (partial) · STIG oracle linux 9 1 (mostly) · STIG rhel 8 1 (mostly) · STIG rhel 9 1 (partial) · STIG windows server 2016 1 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A04:2025 Cryptographic Failures.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
—
- 14 hardening rules · 7 OS baselines
V11.4.2V14.1.2V14.2.4
NIST 800-53 r5 controls that address this weakness (5)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
SC-12 | Cryptographic Key Establishment and Management | SC | Establishment procedures require selection and generation of keys with adequate length and strength for the chosen algorithm. |
SC-13 | Cryptographic Protection | SC | Specifies required cryptography types and parameters, preventing selection of inadequate encryption strength. |
PM-15 | Security and Privacy Groups and Associations | PM | Maintaining currency with technologies and practices reduces selection of encryption mechanisms that provide inadequate strength. |
RA-4 | Risk Assessment Update | RA | Updated assessments identify when previously adequate encryption strength no longer meets current attack capabilities or compliance drivers. |
SI-2 | Flaw Remediation | SI | Prompt patching corrects inadequate encryption strength when vendors release updates that increase key sizes or algorithm security. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2017-11317 KEV UPD | 9.9 | 9.8 | 0.8348 | 2017-08-23 |
CVE-2017-1000486 KEV UPD | 9.9 | 9.8 | 0.9410 | 2018-01-03 |
CVE-2018-15811 KEV UPD | 8.5 | 7.5 | 0.7405 | 2019-07-03 |
CVE-2018-18325 KEV UPD | 8.5 | 7.5 | 0.7405 | 2019-07-03 |
CVE-2014-0224 UPD | 8.3 | 7.4 | 0.9533 | 2014-06-05 |
CVE-2017-7903 UPD | 7.8 | 9.8 | 0.0276 | 2017-06-30 |
CVE-2020-6966 UPD | 7.8 | 10.0 | 0.0222 | 2020-01-24 |
CVE-2018-7242 UPD | 7.7 | 9.8 | 0.0195 | 2018-04-18 |
CVE-2018-0448 UPD | 7.7 | 9.8 | 0.0214 | 2018-10-05 |
CVE-2011-4121 UPD | 7.7 | 9.8 | 0.0253 | 2019-11-26 |
CVE-2013-2166 UPD | 7.7 | 9.8 | 0.0215 | 2019-12-10 |
CVE-2017-7905 UPD | 7.6 | 9.8 | 0.0128 | 2017-06-30 |
CVE-2017-7673 UPD | 7.6 | 9.8 | 0.0165 | 2017-07-17 |
CVE-2018-20810 UPD | 7.6 | 9.8 | 0.0177 | 2019-06-28 |
CVE-2013-7287 UPD | 7.6 | 9.8 | 0.0143 | 2020-02-13 |
CVE-2016-5804 UPD | 7.5 | 9.8 | 0.0112 | 2016-07-15 |
CVE-2017-8076 UPD | 7.5 | 9.8 | 0.0090 | 2017-04-23 |
CVE-2017-7888 UPD | 7.5 | 9.8 | 0.0107 | 2017-05-10 |
CVE-2018-15124 UPD | 7.5 | 9.8 | 0.0107 | 2018-08-13 |
CVE-2019-10907 UPD | 7.5 | 9.8 | 0.0092 | 2019-04-07 |
CVE-2019-15805 UPD | 7.5 | 9.8 | 0.0119 | 2019-08-29 |
CVE-2019-15806 UPD | 7.5 | 9.8 | 0.0119 | 2019-08-29 |
CVE-2019-16649 UPD | 7.5 | 10.0 | 0.0092 | 2019-09-21 |
CVE-2020-10275 UPD | 7.5 | 9.8 | 0.0096 | 2020-06-24 |
CVE-2021-42216 UPD | 7.5 | 9.8 | 0.0116 | 2021-12-15 |