CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,289 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 9 of 26
- CVE-2026-20138MEDIUMCVSS 4.9EG 6.82026-02-18
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the Splunk `_internal` index could view the `integrationKey`, `secretKey…
- CVE-2021-21508MEDIUMCVSS 6.7EG 6.72026-05-22
Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin user may exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to …
- CVE-2022-27599MEDIUMCVSS 6.7EG 6.72023-09-08
An insertion of sensitive information into Log file vulnerability has been reported to affect product. If exploited, the vulnerability possibly provides local authenticated administrators with an additional, less-protected path to acquirin…
- CVE-2023-2514MEDIUMCVSS 6.7EG 6.72023-05-12
Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization.
- CVE-2022-31239MEDIUMCVSS 6.7EG 6.72022-10-21
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log files vulnerability. A privileged local user may potentially exploit this vulnerability, leading to disclosure of this…
- CVE-2021-36318MEDIUMCVSS 6.7EG 6.72021-12-21
Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentially exploit this vulnerability, leading to a complete outage.
- CVE-2021-39913MEDIUMCVSS 6.7EG 6.72021-11-05
Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows an attacker with local f…
- CVE-2019-18576MEDIUMCVSS 6.7EG 6.72020-03-13
Dell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords are logged in local files. Malicious local users with access to the log files may use the exposed passwords to gain ac…
- CVE-2026-44105MEDIUMCVSS 6.6EG 6.62026-07-30
The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.
- CVE-2025-43937MEDIUMCVSS 6.6EG 6.62026-04-16
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to the disclos…
- CVE-2024-47570MEDIUMCVSS 6.6EG 6.62025-12-09
An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all versions; FortiProxy 7.4.0 through 7.4.3, 7.2.0 through 7.2.11; FortiPAM 1.4 all versions, 1.3 all ver…
- CVE-2024-57957MEDIUMCVSS 6.6EG 6.62025-02-06
Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2022-3191MEDIUMCVSS 6.6EG 6.62022-11-01
Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Analyzer on Linux (Virtual Strage Software Agent component) allows local users to gain sensitive information. This issue affects Hitachi Ops Center Analyz…
- CVE-2026-106504MEDIUMCVSS 6.5EG 6.52026-10-06
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder task logs. An authenticated user who can create and…
- CVE-2026-63689MEDIUMCVSS 6.5EG 6.52026-10-06
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to I…
- CVE-2026-81862MEDIUMCVSS 6.5EG 6.52026-09-29
Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` and `AzureBlobStorageToTeradataOperator` interpolate the source bucket's credentials as plain string literals into t…
- CVE-2026-92237MEDIUMCVSS 6.5EG 6.52026-09-15
Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protection…
- CVE-2026-82434MEDIUMCVSS 6.5EG 6.52026-09-14
Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration verbatim to any call…
- CVE-2026-86597MEDIUMCVSS 6.5EG 6.52026-09-08
Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be w…
- CVE-2026-85171MEDIUMCVSS 6.5EG 6.52026-09-03
n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes. These nodes send their decrypted credentials to the authentication endpoint via the raw legacy HTTP helper o…
- CVE-2026-55221MEDIUMCVSS 6.5EG 6.52026-09-02
Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, Boruta logged sensitive OAuth and OpenID Connect values in business event…
- CVE-2026-68969MEDIUMCVSS 6.5EG 6.52026-08-12
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recog…
- CVE-2026-18710MEDIUMCVSS 6.5EG 6.52026-08-11
A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs automatical…
- CVE-2026-71474MEDIUMCVSS 6.5EG 6.52026-08-11
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read thi…
- CVE-2026-65945MEDIUMCVSS 6.5EG 6.52026-08-10
Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.
- CVE-2026-20289MEDIUMCVSS 6.5EG 6.52026-08-05
A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker co…
- CVE-2026-65589MEDIUMCVSS 6.5EG 6.52026-07-22
n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can r…
- CVE-2026-46514MEDIUMCVSS 6.5EG 6.52026-07-16
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword.php:48-53 returned a plaintext password and fm_add_extension in Tools/AddExtension.php:172 returned a plaintext secret…
- CVE-2026-54704MEDIUMCVSS 6.5EG 6.52026-07-01
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.28.0, the JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when…
- CVE-2026-11820MEDIUMCVSS 6.5EG 6.52026-06-23
A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the Vonage/Nexmo SMS API by encoding API credentials (api_key and api_secret) into URL query parameters and sending them vi…
- CVE-2026-41185MEDIUMCVSS 6.5EG 6.52026-05-28
When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to attach subnet information before delegating to the IPAM plugin. After mutating, the Azure IPAM helper logs the entire unm…
- CVE-2026-41184MEDIUMCVSS 6.5EG 6.52026-05-28
In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration template uses the __SERVICEACCOUNT_TOKEN__ placeholder (Canal/Flannel-Calico deployments), the installer substitutes t…
- CVE-2026-45679MEDIUMCVSS 6.5EG 6.52026-05-18
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI exports raw Redis error text as the span status message. Because Redis error replies can contain attacker-con…
- CVE-2026-41219MEDIUMCVSS 6.5EG 6.52026-05-13
An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file. Note: Software versions which have reached End of Technical Support (Eo…
- CVE-2026-43826MEDIUMCVSS 6.5EG 6.52026-05-11
The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:9200`), wrote the full host URL — including the embedded credentials — into task logs. An…
- CVE-2026-41018MEDIUMCVSS 6.5EG 6.52026-05-11
The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:9200`), wrote the full host URL — including the embedded credentials — into task logs.…
- CVE-2026-4901MEDIUMCVSS 6.5EG 6.52026-04-09
AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive infor…
- CVE-2026-4819MEDIUMCVSS 6.5EG 6.52026-03-31
In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.
- CVE-2026-32598MEDIUMCVSS 6.5EG 6.52026-03-13
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is enabled by default…
- CVE-2026-20165MEDIUMCVSS 6.5EG 6.52026-03-11
In Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.7, 10.1.2507.17, 10.0.2503.12, and 9.3.2411.124, a low-privileged user that does not hold the "admin" or "power" Splu…
- CVE-2026-29184MEDIUMCVSS 6.5EG 6.52026-03-07
Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs. This issue has been p…
- CVE-2026-24308MEDIUMCVSS 6.5EG 6.52026-03-07
Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values are …
- CVE-2025-27555MEDIUMCVSS 6.5EG 6.52026-02-24
Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection parameters were set via airflow CLI, value…
- CVE-2026-2350MEDIUMCVSS 6.5EG 6.52026-02-20
Tanium addressed an insertion of sensitive information into log file vulnerability in Interact and TDS.
- CVE-2026-1292MEDIUMCVSS 6.5EG 6.52026-02-20
Tanium addressed an insertion of sensitive information into log file vulnerability in Trends.
- CVE-2026-1495MEDIUMCVSS 6.5EG 6.52026-02-10
The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy details, including URL and proxy credentials, from the PI to CONNECT event log files. This could enable unauthorized a…
- CVE-2026-25846MEDIUMCVSS 6.5EG 6.52026-02-09
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
- CVE-2025-59355MEDIUMCVSS 6.5EG 6.52026-01-19
A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter string in the log via logger.error(str + "decode failed", e). If the input parameter contai…
- CVE-2025-64650MEDIUMCVSS 6.5EG 6.52025-12-08
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files.
- CVE-2025-11446MEDIUMCVSS 6.5EG 6.52025-11-19
Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This issue affects upKeeper Manager: from 5.2.0 before 5.2.12.
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →