CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,213 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 23 of 25
- CVE-2026-21222MEDIUMCVSS 5.5EG 5.52026-02-10
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- CVE-2026-21766MEDIUMCVSS 5.4EG 5.42026-08-05
The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive information may be written to web server…
- CVE-2026-21786LOWCVSS 3.3EG 3.32026-03-05
HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs.
- CVE-2026-21791LOWCVSS 3.3EG 3.32026-03-10
HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URL
- CVE-2026-21808MEDIUMCVSS 4.1EG 4.12026-08-26
HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker with internal application logic and architectural details.
- CVE-2026-22038HIGHCVSS 8.1EG 8.12026-02-04
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.46, the AutoGPT platform's Stagehand integration blocks lo…
- CVE-2026-22098CRITICALCVSS 9.2EG 9.22026-07-13
Various sensitive information such as passwords and charging card UIDs are written to log files.
- CVE-2026-22778CRITICALCVSS 9.8EG 9.82026-02-02
vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap …
- CVE-2026-22782HIGHCVSS 7.5EG 7.52026-01-16
RustFS is a distributed object storage system built in Rust. From >= 1.0.0-alpha.1 to 1.0.0-alpha.79, invalid RPC signatures cause the server to log the shared HMAC secret (and expected signature), which exposes the secret to log readers a…
- CVE-2026-22798MEDIUMCVSS 5.0EG 5.02026-01-12
hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata. From 0.8.1 to before 0.9.1, hermes subcommands take arbitrary options under the -O argument. These have been logged in raw form. If u…
- CVE-2026-23493MEDIUMCVSS 4.9EG 4.92026-01-15
Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file stores the $_COOKIE and $_SERVER variables, which means sensitive information such as database passwords, cookie session …
- CVE-2026-2350MEDIUMCVSS 6.5EG 6.52026-02-20
Tanium addressed an insertion of sensitive information into log file vulnerability in Interact and TDS.
- CVE-2026-23775HIGHCVSS 7.6EG 7.62026-04-17
Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10 contain an insertion of sensitive information into log file vu…
- CVE-2026-2401MEDIUMCVSS 5.0EG 5.02026-04-14
CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Admin user executes a malicious file provided by an attacker.
- CVE-2026-24308MEDIUMCVSS 6.5EG 6.52026-03-07
Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values are …
- CVE-2026-24762HIGHCVSS 7.5EG 7.52026-02-03
RustFS is a distributed object storage system built in Rust. From versions alpha.13 to alpha.81, RustFS logs sensitive credential material (access key, secret key, session token) to application logs at INFO level. This results in credentia…
- CVE-2026-25193HIGHCVSS 8.6EG 8.62026-05-25
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom …
- CVE-2026-25211LOWCVSS 3.2EG 3.22026-01-30
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.
- CVE-2026-25813HIGHCVSS 7.5EG 7.52026-02-09
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The application logs highly sensitive data directly to console output without masking or redaction.
- CVE-2026-25846MEDIUMCVSS 6.5EG 6.52026-02-09
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
- CVE-2026-25918MEDIUMCVSS 5.5EG 5.52026-02-09
unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Command-line arguments i…
- CVE-2026-2605MEDIUMCVSS 5.3EG 5.32026-02-20
Tanium addressed an insertion of sensitive information into log file vulnerability in TanOS.
- CVE-2026-2607MEDIUMCVSS 5.1EG 5.12026-05-27
IBM MQ Operator SC2: v3.2.0 through 3.2.23CD: v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0 - v3.7.2, v3.8.0, v3.8.1, v3.9.0, v3.9.1LTS: v2.0.0 - 2.0.29 and IBM supplied MQ Advanced container images SC2: 9.4.0.…
- CVE-2026-27315MEDIUMCVSS 5.5EG 5.52026-04-07
Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from previously executed cqlsh command via ~/.cassandra/cqlsh_history local file access. Users are recommended to upgra…
- CVE-2026-27900HIGHCVSS 7.7EG 7.72026-02-26
The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackScript content, and object storage data in debug logs without redaction. Provider debug logging is not enabled by defaul…
- CVE-2026-28261HIGHCVSS 5.5EG 7.82026-04-08
Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0.0, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local a…
- CVE-2026-28868MEDIUMCVSS 5.5EG 5.52026-03-25
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. An app may…
- CVE-2026-28923HIGHCVSS 8.8EG 8.82026-05-11
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app may be able to break out of its sandbox.
- CVE-2026-28943HIGHCVSS 7.5EG 7.52026-05-11
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be …
- CVE-2026-28987HIGHCVSS 7.5EG 7.52026-05-11
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be …
- CVE-2026-29184MEDIUMCVSS 6.5EG 6.52026-03-07
Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs. This issue has been p…
- CVE-2026-31987HIGHCVSS 7.5EG 7.52026-04-16
JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. Users are recommended to upgrade to version 3.2.0, which fixes this issue.
- CVE-2026-32215MEDIUMCVSS 5.5EG 5.52026-04-14
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- CVE-2026-32217MEDIUMCVSS 5.5EG 5.52026-04-14
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- CVE-2026-32218MEDIUMCVSS 5.5EG 5.52026-04-14
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- CVE-2026-32598MEDIUMCVSS 6.5EG 6.52026-03-13
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is enabled by default…
- CVE-2026-32982HIGHCVSS 7.5EG 7.52026-03-31
OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot token…
- CVE-2026-32996HIGHCVSS 7.3EG 7.32026-05-28
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
- CVE-2026-34164MEDIUMCVSS 4.9EG 4.92026-04-16
Valtimo is an open-source business process automation platform. In versions 13.0.0 through 13.21.0, the InboxHandlingService logs the full content of every incoming inbox message at INFO level. Inbox messages can contain highly sensitive i…
- CVE-2026-34487HIGHCVSS 7.5EG 7.52026-04-09
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 1…
- CVE-2026-35185HIGHCVSS 7.5EG 7.52026-04-06
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is publicly accessible and exposes sensitive information including authentication tokens (user_token), user activity, client …
- CVE-2026-40091MEDIUMCVSS 6.0EG 6.02026-04-15
SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions 1.49.0 through 1.51.0, when SpiceDB starts with log level info, the startup "configuration" log will include the ful…
- CVE-2026-40619HIGHCVSS 7.8EG 7.82026-06-02
A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privileges to the main server to access the Server Admin credentials. A third party hired by Ge…
- CVE-2026-40633HIGHCVSS 5.5EG 7.82026-07-15
Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit t…
- CVE-2026-40945HIGHCVSS 8.7EG 8.72026-04-21
Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, the full bearer token is logged at DEBUG level in plaintext. If debug logging is enabled in production, JWT tokens are exposed in applicatio…
- CVE-2026-41004MEDIUMCVSS 4.4EG 4.42026-05-07
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Suppo…
- CVE-2026-41018MEDIUMCVSS 6.5EG 6.52026-05-11
The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:9200`), wrote the full host URL — including the embedded credentials — into task logs.…
- CVE-2026-41182MEDIUMCVSS 5.3EG 5.32026-04-23
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_out…
- CVE-2026-41184MEDIUMCVSS 6.5EG 6.52026-05-28
In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration template uses the __SERVICEACCOUNT_TOKEN__ placeholder (Canal/Flannel-Calico deployments), the installer substitutes t…
- CVE-2026-41185MEDIUMCVSS 6.5EG 6.52026-05-28
When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to attach subnet information before delegating to the IPAM plugin. After mutating, the Azure IPAM helper logs the entire unm…
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →