CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,213 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 24 of 25
- CVE-2026-41219MEDIUMCVSS 6.5EG 6.52026-05-13
An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file. Note: Software versions which have reached End of Technical Support (Eo…
- CVE-2026-41495MEDIUMCVSS 5.3EG 5.32026-05-08
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.11, when n8n-mcp runs in HTTP transport mode, incoming requests to the POST /mcp endpoint had their re…
- CVE-2026-42282MEDIUMCVSS 4.3EG 4.32026-05-08
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.13, when n8n-mcp runs in HTTP transport mode, authenticated MCP tools/call requests had their full arg…
- CVE-2026-43826MEDIUMCVSS 6.5EG 6.52026-05-11
The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:9200`), wrote the full host URL — including the embedded credentials — into task logs. An…
- CVE-2026-43992CRITICALCVSS 9.8EG 9.82026-05-12
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate_contract, upload_wasm, ibc_transfer, etc.) accepted 'mnemonic: string' as an explicit too…
- CVE-2026-44052HIGHCVSS 7.5EG 7.52026-05-21
Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which allows an attacker with access to the log files to obtain LDAP credentials.
- CVE-2026-44105MEDIUMCVSS 6.6EG 6.62026-07-30
The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.
- CVE-2026-44479MEDIUMCVSS 5.5EG 5.52026-05-13
Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI runs in non-interactive mode (--non-interactive or auto-detected AI agent), commands that cannot complete autonomously …
- CVE-2026-44516HIGHCVSS 7.6EG 7.62026-05-14
Valtimo is an open-source business process automation platform. From 12.4.0 to 12.33.0 and 13.26.0, the LoggingRestClientCustomizer in the web module automatically intercepts all outgoing HTTP calls made via Spring's RestClient and logs th…
- CVE-2026-44969LOWCVSS 3.3EG 3.32026-07-16
dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary at INFO level before each tool call and at ERROR level on exceptions,…
- CVE-2026-45040MEDIUMCVSS 5.3EG 5.32026-05-28
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive information leakage in log outputs. When the server is run with RUST_LOG=debug sensitive credentials including SessionToken (…
- CVE-2026-45581MEDIUMCVSS 5.5EG 5.52026-05-19
fabric-chaincode-java is a Java based implementation of Hyperledger Fabric chaincode shim APIs. From version 2.3.1 to before version 2.5.10, when chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server I…
- CVE-2026-45679MEDIUMCVSS 6.5EG 6.52026-05-18
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI exports raw Redis error text as the span status message. Because Redis error replies can contain attacker-con…
- CVE-2026-46358MEDIUMCVSS 5.4EG 5.42026-05-28
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers be…
- CVE-2026-46467MEDIUMCVSS 5.8EG 5.82026-07-03
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an insertion of se…
- CVE-2026-46514MEDIUMCVSS 6.5EG 6.52026-07-16
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword.php:48-53 returned a plaintext password and fm_add_extension in Tools/AddExtension.php:172 returned a plaintext secret…
- CVE-2026-47234MEDIUMCVSS 4.4EG 4.42026-05-29
Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::setCookie()` logs full cookie values and `Session::start()` logs the current session ID. In a real Admidio deployment thi…
- CVE-2026-4788HIGHCVSS 5.5EG 8.42026-04-08
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files that could be read by a local user.
- CVE-2026-4819MEDIUMCVSS 6.5EG 6.52026-03-31
In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.
- CVE-2026-4901MEDIUMCVSS 6.5EG 6.52026-04-09
AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive infor…
- CVE-2026-49088MEDIUMCVSS 4.4EG 4.42026-07-01
Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the optional application performance monitoring (APM) instrumentation is enabled, sensitive request header values could be record…
- CVE-2026-49200CRITICALCVSS 9.8EG 9.82026-05-29
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.
- CVE-2026-4957LOWCVSS 2.7EG 2.72026-03-27
A flaw has been found in OpenBMB XAgent 1.0.0. The impacted element is the function FunctionHandler.handle_tool_call of the file XAgent/function_handler.py of the component API Key Handler. This manipulation of the argument api_key causes …
- CVE-2026-50205HIGHCVSS 8.2EG 8.22026-06-04
System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.
- CVE-2026-50316MEDIUMCVSS 5.5EG 5.52026-07-14
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- CVE-2026-54236MEDIUMCVSS 5.3EG 5.32026-06-17
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778, which introduced a sanitize_message helper that strips object-repr memory addresses from error messages before they r…
- CVE-2026-54652HIGHCVSS 8.1EG 8.12026-07-08
Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the viewer role to download Frigate and nginx logs, exposing auto-generated admin passwords a…
- CVE-2026-54704MEDIUMCVSS 6.5EG 6.52026-07-01
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.28.0, the JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when…
- CVE-2026-54711LOWEG not assessed2026-06-18
PGHoard: Password written to debug log ### Impact When using .pgpass, database connection information including the username and password will be logged at the debug level. ### Patches Upgrade to version 2.7.1 or greater. ### Workaround…
- CVE-2026-5515MEDIUMCVSS 5.5EG 5.52026-05-27
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user.
- CVE-2026-56457MEDIUMCVSS 4.3EG 4.32026-06-29
HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step.
- CVE-2026-56459MEDIUMCVSS 5.5EG 6.22026-07-09
HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially sensitive information in log files that could be read by a local user.
- CVE-2026-58070MEDIUMCVSS 6.8EG 6.82026-08-26
A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that log to recover privileged account credentials.
- CVE-2026-59326LOWCVSS 3.3EG 3.32026-07-30
The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configur…
- CVE-2026-59911MEDIUMCVSS 5.5EG 5.52026-08-17
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low privileged attacker with local access could potentially exploit this vulnerability, leading t…
- CVE-2026-59947MEDIUMCVSS 4.7EG 4.72026-07-08
Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print a credential embedded in the username slot of a repository or package URL, such as a GitHub P…
- CVE-2026-62211MEDIUMCVSS 5.0EG 5.02026-07-17
OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misco…
- CVE-2026-64800MEDIUMCVSS 5.7EG 5.72026-07-23
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
- CVE-2026-65311MEDIUMCVSS 5.3EG 5.32026-07-31
The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attac…
- CVE-2026-65589MEDIUMCVSS 6.5EG 6.52026-07-22
n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can r…
- CVE-2026-65945MEDIUMCVSS 6.5EG 6.52026-08-10
Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.
- CVE-2026-6720HIGHCVSS 7.2EG 7.22026-05-28
When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embeds every credential calicoctl uses to ta…
- CVE-2026-68969MEDIUMCVSS 6.5EG 6.52026-08-12
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recog…
- CVE-2026-71474MEDIUMCVSS 6.5EG 6.52026-08-11
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read thi…
- CVE-2026-71845HIGHCVSS 7.7EG 7.72026-08-11
A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to leve…
- CVE-2026-74870LOWCVSS 3.3EG 3.32026-08-17
openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hsm onlykey-test' diagnostic commands unconditionally print the full derived hardware pepper as hex to stdout/stderr (cry…
- CVE-2026-75057MEDIUMCVSS 6.2EG 6.22026-08-17
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
- CVE-2026-75485MEDIUMCVSS 5.5EG 5.52026-08-18
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exp…
- CVE-2026-75573MEDIUMCVSS 4.4EG 4.42026-08-27
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured…
- CVE-2026-76374MEDIUMCVSS 4.3EG 4.32026-08-19
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause sensitive Active Directory response data to be written to a persistent debug log file by triggering write operat…
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →