CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,289 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 14 of 26
- CVE-2026-78631MEDIUMCVSS 5.5EG 5.52026-09-08
The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authenti…
- CVE-2026-68873MEDIUMCVSS 5.5EG 5.52026-09-08
Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally.
- CVE-2026-80056MEDIUMCVSS 5.5EG 5.52026-09-07
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could po…
- CVE-2026-17442MEDIUMCVSS 5.5EG 5.52026-09-04
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written …
- CVE-2026-75573MEDIUMCVSS 5.5EG 5.52026-08-27
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured…
- CVE-2026-75485MEDIUMCVSS 5.5EG 5.52026-08-18
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exp…
- CVE-2026-59911MEDIUMCVSS 5.5EG 5.52026-08-17
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low privileged attacker with local access could potentially exploit this vulnerability, leading t…
- CVE-2026-18097MEDIUMCVSS 5.5EG 5.52026-08-12
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.
- CVE-2026-19502MEDIUMCVSS 5.5EG 5.52026-08-12
MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings were written without redaction, so authentication material supplied b…
- CVE-2026-50316MEDIUMCVSS 5.5EG 5.52026-07-14
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- CVE-2026-13750MEDIUMCVSS 5.5EG 5.52026-06-29
Insertion of sensitive information into log files in Snowflake CLI versions prior to 3.19 allowed plaintext credentials to be written to persistent local debug logs. An attacker could exploit this by obtaining read access to the affected u…
- CVE-2025-59868MEDIUMCVSS 5.5EG 5.52026-06-27
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit application information to then attempt additional attacks and cause unknown behavior in the appli…
- CVE-2026-11819MEDIUMCVSS 5.5EG 5.52026-06-23
Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from the OS native keyring (GNOME Keyring, macOS Keychain, Windows Credential Manager) and pl…
- CVE-2025-46313MEDIUMCVSS 5.5EG 5.52026-06-11
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
- CVE-2026-0267MEDIUMCVSS 5.5EG 5.52026-06-10
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is kn…
- CVE-2026-9751MEDIUMCVSS 5.5EG 5.52026-06-09
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
- CVE-2026-9735MEDIUMCVSS 5.5EG 5.52026-06-09
MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without reda…
- CVE-2026-5515MEDIUMCVSS 5.5EG 5.52026-05-27
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user.
- CVE-2025-13755MEDIUMCVSS 5.5EG 5.52026-05-26
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local user.
- CVE-2026-45581MEDIUMCVSS 5.5EG 5.52026-05-19
fabric-chaincode-java is a Java based implementation of Hyperledger Fabric chaincode shim APIs. From version 2.3.1 to before version 2.5.10, when chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server I…
- CVE-2026-44479MEDIUMCVSS 5.5EG 5.52026-05-13
Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI runs in non-interactive mode (--non-interactive or auto-detected AI agent), commands that cannot complete autonomously …
- CVE-2026-32218MEDIUMCVSS 5.5EG 5.52026-04-14
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- CVE-2026-32217MEDIUMCVSS 5.5EG 5.52026-04-14
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- CVE-2026-32215MEDIUMCVSS 5.5EG 5.52026-04-14
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- CVE-2026-27315MEDIUMCVSS 5.5EG 5.52026-04-07
Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from previously executed cqlsh command via ~/.cassandra/cqlsh_history local file access. Users are recommended to upgra…
- CVE-2026-28868MEDIUMCVSS 5.5EG 5.52026-03-25
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. An app may…
- CVE-2026-20668MEDIUMCVSS 5.5EG 5.52026-03-25
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3, visionOS 26.3. An app may be able to ac…
- CVE-2026-21222MEDIUMCVSS 5.5EG 5.52026-02-10
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- CVE-2026-25918MEDIUMCVSS 5.5EG 5.52026-02-09
unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Command-line arguments i…
- CVE-2025-43508MEDIUMCVSS 5.5EG 5.52026-01-16
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
- CVE-2025-43475MEDIUMCVSS 5.5EG 5.52025-12-17
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2. An app may be able to access user-sensitive data.
- CVE-2025-43538MEDIUMCVSS 5.5EG 5.52025-12-12
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sonoma 14.8.3, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An app may be able to access sen…
- CVE-2025-14010MEDIUMCVSS 5.5EG 5.52025-12-04
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible with debug modes. Attacke…
- CVE-2025-66411MEDIUMCVSS 5.5EG 5.52025-12-03
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests containing sensitive values were logged in plaintext unsanitized. An attacker with limite…
- CVE-2025-62209MEDIUMCVSS 5.5EG 5.52025-11-11
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
- CVE-2025-62208MEDIUMCVSS 5.5EG 5.52025-11-11
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
- CVE-2025-12940MEDIUMCVSS 5.5EG 5.52025-11-11
Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6 Access Points). An user having access to the syslog server can read …
- CVE-2025-43426MEDIUMCVSS 5.5EG 5.52025-11-04
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may be able to access sensitive user data.
- CVE-2025-59203MEDIUMCVSS 5.5EG 5.52025-10-14
Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally.
- CVE-2025-59197MEDIUMCVSS 5.5EG 5.52025-10-14
Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally.
- CVE-2025-47979MEDIUMCVSS 5.5EG 5.52025-10-14
Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.
- CVE-2025-36144MEDIUMCVSS 5.5EG 5.52025-09-27
IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user.
- CVE-2025-43354MEDIUMCVSS 5.5EG 5.52025-09-15
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to access sensitive user data.
- CVE-2025-43303MEDIUMCVSS 5.5EG 5.52025-09-15
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to access sensitive user data.
- CVE-2025-10221MEDIUMCVSS 5.5EG 5.52025-09-10
Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via reading …
- CVE-2025-23261MEDIUMCVSS 5.5EG 5.52025-09-04
NVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed in log files, potentially disclosing information to unauthorized users.
- CVE-2025-23289MEDIUMCVSS 5.5EG 5.52025-07-31
NVIDIA Omniverse Launcher for Windows and Linux contains a vulnerability in the launcher logs, where a user could cause sensitive information to be written to the log files through proxy servers. A successful exploit of this vulnerability …
- CVE-2025-43225MEDIUMCVSS 5.5EG 5.52025-07-30
A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data.
- CVE-2025-51497MEDIUMCVSS 5.5EG 5.52025-07-17
An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Safari accessed when the plugin was active. These logs went into the MacOS general logs for any unsandboxed process to rea…
- CVE-2025-30483MEDIUMCVSS 5.5EG 5.52025-07-15
Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading t…
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →