CWE-532
CVEs classified under CWE-532, newest first.
118 CVEsRSS
GHSA-p77j-g7h5-r2vwHighGeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
GHSA-hjwh-xvfw-qrwjMedium· 5.5SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
CVE-2026-66780Medium· 6.5A flaw was found in the submariner-operator component
A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, sp…
CVE-2026-75485Medium· 5.5A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This e…
CVE-2026-75057Medium· 6.2In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
CVE-2026-47234Medium· 4.4Admidio is an open-source user management solution
Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::setCookie()` logs full cookie values and `Session::start()` logs the current session ID. In a real Admidio deployment t…
CVE-2026-68969Medium· 6.5Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`)
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking rec…
CVE-2026-18097Medium· 5.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.
CVE-2026-71845Medium· 6.3A flaw was found in insights-client
A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to le…
CVE-2026-71474High· 7.1A flaw was found in insights-client
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read t…
CVE-2026-18710Medium· 6.5A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization
A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs automatic…
CVE-2026-46358MediumOpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers …
CVE-2026-59326Low· 3.3The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is config…
The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is config…
CVE-2026-54704Medium· 6.5OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
GHSA-2625-rw7m-5q5xLowHubuum client library (Rust): Sensitive data may be exposed through default diagnostics
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics
GHSA-fmvg-vhqq-r2mjMediumDuplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
CVE-2026-65589Mediumn8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
CVE-2026-59947Medium· 4.7Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
CVE-2026-50316Medium· 5.5Windows Kernel Information Disclosure Vulnerability
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-46467Medium· 5.8Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an insertion of …
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an insertion of …
CVE-2026-56457Medium· 4.3HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs
HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step.
GHSA-q683-8468-r6h6MediumWebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs
WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs
CVE-2026-11819Medium· 5.5Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from the OS native keyring (GNOME Keyring, macOS Keychain, Windows Credential Manager) and pl…
Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from the OS native keyring (GNOME Keyring, macOS Keychain, Windows Credential Manager) and pl…
CVE-2026-9073Medium· 6.2A flaw was found in foreman-mcp-server
A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, which are treated as authentication creden…
CVE-2026-54711LowPGHoard: Password written to debug log
PGHoard: Password written to debug log
CVE-2026-54236Medium· 5.3PoCvLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
CVE-2026-47768Medium· 5.5nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)
CVE-2026-0267Medium· 5.5An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is …
CVE-2026-32996High· 7.3PoCThis vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
CVE-2026-20239High· 7.5In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session coo…
In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session coo…