CWE-532— Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.— MITRE CWE catalog
1,256 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-532page 25 of 26
- CVE-2026-65945MEDIUMCVSS 6.5EG 6.52026-08-10
Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.
- CVE-2026-66780CRITICALCVSS 6.5EG 9.92026-08-18
A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, spec…
- CVE-2026-6720HIGHCVSS 7.2EG 7.22026-05-28
When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embeds every credential calicoctl uses to ta…
- CVE-2026-68873MEDIUMCVSS 5.5EG 5.52026-09-08
Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally.
- CVE-2026-68969MEDIUMCVSS 6.5EG 6.52026-08-12
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recog…
- CVE-2026-71474MEDIUMCVSS 6.5EG 6.52026-08-11
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read thi…
- CVE-2026-71845HIGHCVSS 7.7EG 7.72026-08-11
A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to leve…
- CVE-2026-73442LOWCVSS 3.0EG 3.02026-09-16
On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a sys…
- CVE-2026-73457MEDIUMCVSS 5.3EG 5.32026-09-16
Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting logs to authenticate…
- CVE-2026-73465MEDIUMCVSS 6.3EG 6.32026-09-15
On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To explo…
- CVE-2026-73466MEDIUMCVSS 6.3EG 6.32026-09-15
On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit thes…
- CVE-2026-73467MEDIUMCVSS 6.3EG 6.32026-09-15
On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers
- CVE-2026-74870LOWCVSS 3.3EG 3.32026-08-17
openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hsm onlykey-test' diagnostic commands unconditionally print the full derived hardware pepper as hex to stdout/stderr (cry…
- CVE-2026-75057MEDIUMCVSS 6.2EG 6.22026-08-17
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
- CVE-2026-75485MEDIUMCVSS 5.5EG 5.52026-08-18
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exp…
- CVE-2026-75573MEDIUMCVSS 4.4EG 4.42026-08-27
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured…
- CVE-2026-76374MEDIUMCVSS 4.3EG 4.32026-08-19
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause sensitive Active Directory response data to be written to a persistent debug log file by triggering write operat…
- CVE-2026-76375MEDIUMCVSS 5.0EG 5.02026-08-19
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive credentials by invoking an action that causes the full connector process environment to be written to…
- CVE-2026-78174CRITICALCVSS 9.3EG 9.32026-08-27
WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that admin…
- CVE-2026-7824MEDIUMCVSS 5.9EG 5.92026-05-05
An issue was discovered in the PaperCut Hive Ricoh embedded application. When the "Deep Logging" (diagnostic) mode is enabled, the application inadvertently records administrative credentials in plain text within the log files. An attac…
- CVE-2026-78627HIGHCVSS 7.3EG 7.32026-09-08
The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of w…
- CVE-2026-78631MEDIUMCVSS 5.3EG 5.32026-09-08
The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authenti…
- CVE-2026-79966LOWCVSS 3.3EG 3.32026-09-09
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could po…
- CVE-2026-80056MEDIUMCVSS 5.5EG 5.52026-09-07
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could po…
- CVE-2026-80124MEDIUMCVSS 5.5EG 5.52026-09-09
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could po…
- CVE-2026-80169LOWCVSS 3.3EG 3.32026-09-09
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could po…
- CVE-2026-81320MEDIUMCVSS 5.5EG 5.52026-09-15
A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialized to JSON and w…
- CVE-2026-81530MEDIUMCVSS 5.6EG 5.62026-08-27
A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material supplied by the application to be reproduced verbatim in the driver's human-readable diagnostic rep…
- CVE-2026-81705HIGHCVSS 7.5EG 7.52026-08-27
openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. --passw). The sanitizer o…
- CVE-2026-81715LOWCVSS 3.3EG 3.32026-08-27
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug argv dump, because sanitize_argv_for_debug fails to sanitize…
- CVE-2026-81870LOWCVSS 2.0EG 2.02026-09-16
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include …
- CVE-2026-8200LOWCVSS 2.7EG 2.72026-05-13
When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the local server log message generated may not have all user data redacted. This issue impacts MongoDB Server v7.0 version…
- CVE-2026-82434MEDIUMCVSS 6.5EG 6.52026-09-14
Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration verbatim to any call…
- CVE-2026-82723LOWCVSS 1.8EG 1.82026-09-17
Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log add-on builds each entry's extra_data in AshAuthentic…
- CVE-2026-8330MEDIUMCVSS 4.4EG 4.42026-06-25
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed sensitive information to be written to application l…
- CVE-2026-84513MEDIUMCVSS 5.5EG 5.52026-09-14
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, wa…
- CVE-2026-84525MEDIUMCVSS 5.5EG 5.52026-09-14
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.
- CVE-2026-84527MEDIUMCVSS 5.5EG 5.52026-09-14
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive u…
- CVE-2026-8482MEDIUMCVSS 4.3EG 4.32026-07-02
A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands have been passed w…
- CVE-2026-85171MEDIUMCVSS 6.5EG 6.52026-09-03
n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes. These nodes send their decrypted credentials to the authentication endpoint via the raw legacy HTTP helper o…
- CVE-2026-85174HIGHCVSS 8.8EG 8.82026-09-03
SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover ad…
- CVE-2026-86049HIGHCVSS 7.1EG 7.12026-09-17
Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token scrubbing used for the…
- CVE-2026-86501LOWCVSS 2.8EG 2.82026-09-07
In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log
- CVE-2026-86597MEDIUMCVSS 6.5EG 6.52026-09-08
Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be w…
- CVE-2026-8671HIGHCVSS 7.5EG 7.52026-05-26
Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure. This issue affects Avantra: before 25.3.0.
- CVE-2026-87779HIGHCVSS 7.5EG 7.52026-09-14
Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes) is configured, Syncope will pad the provided value with random characters. The resulting key valu…
- CVE-2026-87993HIGHCVSS 7.7EG 7.72026-09-10
The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task events.…
- CVE-2026-88883HIGHCVSS 7.7EG 7.72026-09-10
Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), log sanitisation for TLS private keys used for Mu…
- CVE-2026-9073MEDIUMCVSS 6.2EG 6.22026-06-23
A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, which are treated as authentication credenti…
- CVE-2026-92237MEDIUMCVSS 6.5EG 6.52026-09-15
Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protection…
Map vulnerabilities like CWE-532 to your infrastructure
EchelonGraph correlates every CVE — across CWE-532 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →