CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,175 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 24 of 24
- CVE-2026-49200CRITICALCVSS 9.8EG 9.82026-05-29
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.
- CVE-2026-4957LOWCVSS 2.7EG 2.72026-03-27
A flaw has been found in OpenBMB XAgent 1.0.0. The impacted element is the function FunctionHandler.handle_tool_call of the file XAgent/function_handler.py of the component API Key Handler. This manipulation of the argument api_key causes …
- CVE-2026-50205HIGHCVSS 8.2EG 8.22026-06-04
System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.
- CVE-2026-50316MEDIUMCVSS 5.5EG 5.52026-07-14
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- CVE-2026-54236MEDIUMCVSS 5.3EG 5.32026-06-17
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778, which introduced a sanitize_message helper that strips object-repr memory addresses from error messages before they r…
- CVE-2026-54652HIGHCVSS 8.1EG 8.12026-07-08
Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the viewer role to download Frigate and nginx logs, exposing auto-generated admin passwords a…
- CVE-2026-54704MEDIUMCVSS 6.5EG 6.52026-07-01
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.28.0, the JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when…
- CVE-2026-54711LOWEG 0.02026-06-18
PGHoard: Password written to debug log ### Impact When using .pgpass, database connection information including the username and password will be logged at the debug level. ### Patches Upgrade to version 2.7.1 or greater. ### Workaround…
- CVE-2026-5515MEDIUMCVSS 5.5EG 5.52026-05-27
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user.
- CVE-2026-56457MEDIUMCVSS 4.3EG 4.32026-06-29
HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step.
- CVE-2026-56459MEDIUMCVSS 5.5EG 6.22026-07-09
HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially sensitive information in log files that could be read by a local user.
- CVE-2026-59947MEDIUMCVSS 4.7EG 4.72026-07-08
Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print a credential embedded in the username slot of a repository or package URL, such as a GitHub P…
- CVE-2026-62211MEDIUMCVSS 5.0EG 5.02026-07-17
OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misco…
- CVE-2026-64800MEDIUMCVSS 5.7EG 5.72026-07-23
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
- CVE-2026-65589MEDIUMCVSS 6.5EG 6.52026-07-22
n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can r…
- CVE-2026-6720HIGHCVSS 7.2EG 7.22026-05-28
When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embeds every credential calicoctl uses to ta…
- CVE-2026-7824MEDIUMCVSS 5.9EG 5.92026-05-05
An issue was discovered in the PaperCut Hive Ricoh embedded application. When the "Deep Logging" (diagnostic) mode is enabled, the application inadvertently records administrative credentials in plain text within the log files. An attac…
- CVE-2026-8200LOWCVSS 2.7EG 2.72026-05-13
When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the local server log message generated may not have all user data redacted. This issue impacts MongoDB Server v7.0 version…
- CVE-2026-8330MEDIUMCVSS 4.4EG 4.42026-06-25
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed sensitive information to be written to application l…
- CVE-2026-8482MEDIUMCVSS 4.3EG 4.32026-07-02
A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands have been passed w…
- CVE-2026-8671HIGHCVSS 7.5EG 7.52026-05-26
Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure. This issue affects Avantra: before 25.3.0.
- CVE-2026-9073MEDIUMCVSS 6.2EG 6.22026-06-23
A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, which are treated as authentication credenti…
- CVE-2026-9699MEDIUMCVSS 6.8EG 6.82026-06-26
Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server logs or support packets to obtain a valid or partially reconstructab…
- CVE-2026-9735MEDIUMCVSS 5.5EG 5.52026-06-09
MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without reda…
- CVE-2026-9751MEDIUMCVSS 5.5EG 5.52026-06-09
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →